Linux sar Command

Linux 命令大全Linux Command Encyclopedia


1. What is the sar command?

sar (System Activity Reporter) is a powerful performance monitoring tool on Linux systems and is part of the sysstat package. It can collect, report, and save various activity information about the system, including:

  • CPU usage
  • Memory utilization
  • I/O activity
  • Network statistics
  • Process activity
  • Device load, etc.

1.1 Advantages of the sar command

  1. Historical data analysis: Allows you to view the system status at any point in the past
  2. Comprehensive monitoring: Covers all key performance metrics of the system
  3. Low overhead: Data collection has minimal impact on system performance
  4. Automation: Can be configured to automatically collect data periodically

2. Installation and Basic Configuration

2.1 Installing the sysstat Package

On most Linux distributions, the sar command can be obtained by installing the sysstat package:

# Ubuntu/Debian
sudo apt-get install sysstat

# CentOS/RHEL
sudo yum install sysstat

# Fedora
sudo dnf install sysstat

2.2 Enabling Data Collection

After installation, the data collection service needs to be enabled:

Example

# Edit the configuration file
sudo vi /etc/default/sysstat

# Change ENABLED="false" to
ENABLED="true"

# Restart the service
sudo systemctl restart sysstat

By default, sar collects data every 10 minutes and saves it in/var/log/sysstat/the directory.


3. Basic Syntax and Common Parameters

3.1 Basic Syntax Format

sar [选项] [间隔时间] [次数]

3.2 Explanation of Common Parameters

Parameter Description
-A Display all reports
-u Display CPU utilization
-r Display memory usage
-b Display I/O and transfer rate statistics
-n DEV Display network device statistics
-q Display system load and queue length
-d Display disk activity
-P ALL Display statistics for each CPU
-s Specify start time
-e Specify end time
-f Read data from the specified file

4. Practical Application Examples

4.1 Real-time Monitoring of CPU Usage

Example

# Refresh every 2 seconds, display 5 times in total
sar -u 2 5

Example output:

Linux 5.4.0-91-generic (hostname)  03/15/2023  _x86_64_  (4 CPU)

10:30:01 AM     CPU     %user     %nice   %system   %iowait    %steal     %idle
10:30:03 AM     all      5.12      0.00      1.02      0.51      0.00     93.35
10:30:05 AM     all      6.23      0.00      1.34      0.23      0.00     92.20

4.2 View Historical Memory Usage

Example

# View today's memory usage
sar -r

# View data for a specified date (file must be specified)
sar -r -f /var/log/sysstat/sa15  # Data for the 15th

4.3 Monitor Disk I/O Activity

Example

# Monitor disk activity, refresh every 1 second, 10 times total
sar -d 1 10

4.4 View Network Interface Statistics

Example

# Monitor network interface activity
sar -n DEV 1 5

5. Advanced Usage and Tips

5.1 Combining Multiple Metrics for Monitoring

Example

# Monitor CPU, memory, and disk simultaneously
sar -urdb 1 5

5.2 Generate Reports for a Specific Time Period

Example

# View CPU usage from 9 a.m. to 10 a.m.
sar -u -s 09:00:00 -e 10:00:00

5.3 Save Output to a File

Example

# Save monitoring results to a file
sar -A 1 10 > system_report.log

5.4 Monitor a Specific CPU Core

Example

# Monitor CPU0 usage
sar -P 0 1 5

6. Data Interpretation Guide

6.1 CPU Metric Interpretation

Metric Meaning Healthy range
%user User-space CPU usage <70%
%system Kernel-space CPU usage <30%
%iowait CPU waiting for I/O time <5%
%idle CPU idle time >20%

6.2 Memory Metric Interpretation

Metric Meaning
kbmemfree Free physical memory (KB)
kbmemused Used physical memory (KB)
%memused Memory usage rate
kbbuffers Memory used by buffers (KB)
kbcached Memory used by cache (KB)

6.3 Disk Metric Interpretation

Metric Meaning
tps Transfers per second
rd_sec/s Sectors read per second
wr_sec/s Sectors written per second
%util Device utilization

7. Common Troubleshooting

7.1 Identifying CPU Bottlenecks

If%useror%systemremains consistently above 80%, it may indicate:

  • Compute-intensive applications
  • Excessive system calls
  • Need to optimize code or add CPU resources

7.2 Determining Insufficient Memory

When the following conditions occur simultaneously, there may be insufficient memory:

  • %memusedConsistently above 90%
  • kbcachedValue is very low
  • Swap partition (kbswpused) usage is high

7.3 Identifying I/O Bottlenecks

%iowaitHigh and disk%utilHigh indicates:

  • Disk I/O becomes a bottleneck
  • May need faster storage devices
  • Or optimize I/O-intensive operations

Linux 命令大全Linux Command Encyclopedia

Other Extensions