What is running on this box?
A page says "the server is slow" or "memory is almost gone". Before you can fix anything you need a list of every running program, who started it, and what it is doing right now. That list is the process table, and ps prints it.
What you need to know already: 1.15 (PID 1 and parent processes), 1.7 (pipes, | head).
Reminder: a process
A process is one running copy of a program. The kernel (the core of the operating system, which runs the hardware and every program) gives each one a number, the PID, and remembers which process started it: the parent, whose PID is the PPID.
ps, two old spellings
ps (process status) prints the process table once and exits. It has two option styles from two old Unix families, and you will see both in the wild:
ps aux BSD style, no dash
ps -ef UNIX style, with a dash
ps aux: a = processes of all users, u = user-oriented columns, x = also processes with no terminal (services). Its columns:
USER PID %CPU %MEM VSZ RSS TTY STAT START TIME COMMAND
ps -ef: -e = every process, -f = full format. Its columns:
UID PID PPID C STIME TTY TIME CMD
USER/UID- who the process runs as%CPU,%MEM- share of CPU time and of RAM it usesTTY- the terminal it is attached to (pts/0is your SSH login,?= none)START/STIME- when it started;TIME- CPU time used so farCOMMAND/CMD- the command line
The one difference that matters day to day: -ef shows PPID ("who started this?"), aux shows %CPU and %MEM ("what is eating the box?").
Your own columns: -o
ps -eo pid,ppid,user,rss,vsz,stat,etime,comm --sort=-rss | head
-eevery process-o pid,ppid,...output exactly these columns, in this order (etime= elapsed time since start,comm= the short program name)--sort=-rsssort by the RSS column; the-means biggest first| headkeep the first 10 lines
You do not have to remember column names: ps L lists every one.
A trailing = on a column removes its header line, which is what makes ps usable inside $(...) and scripts:
ps -p 1 -o comm= -> systemd (-p 1 = only PID 1)
ps -o ppid= -p $$ -> the PID that started your shell
$$ is a shell variable holding your own shell's PID.
STAT: what the process is doing
The first letter of STAT is the process state:
R running, or runnable: on a CPU, or waiting in the queue for one
S interruptible sleep: waiting for something (a key press, a network
packet, a timer) and can be woken by a signal. Most processes, most of
the time. Perfectly healthy.
D UNINTERRUPTIBLE sleep: waiting inside the kernel, usually for a disk or
a network file server. Signals are not delivered - you CANNOT kill it,
not even with kill -9.
Z zombie: already exited; only a small record is left, waiting for its
parent to collect the exit status.
T stopped: paused (by Ctrl+Z or a stop signal).
I idle kernel thread: the kernel's own helpers, doing nothing.
A signal is a small message the kernel delivers to a process, like "please stop" or "stop now". Lesson 3.6 covers them; for now, kill -9 <pid> is the "stop now" one.
After the letter come modifiers:
s session leader (the first process of a login, e.g. your shell)
l multi-threaded (a thread is one line of work inside a process; a
process can run many at once)
+ in the foreground of its terminal
< high priority N low priority ("niced")
So Ssl is a normal background service with several threads, sleeping until work arrives. D on its own, on twelve processes, is an incident.
RSS vs VSZ, briefly
Two memory columns, and only one of them is useful:
- RSS (resident set size, in KiB) - physical RAM the process is really using right now.
- VSZ (virtual size, in KiB) - every address range it has reserved, including memory it never touched and shared libraries counted in full.
The orders service on this box is a Java program. Java programs run inside the JVM (Java Virtual Machine), a runtime that reserves large address ranges up front, so a JVM using 600 MB of RAM routinely shows 4 GB of VSZ. It means nothing. Sort by RSS. (Chapter 5 shows why even RSS over-counts.)
What you can now do
- List every process with the columns you choose, sorted by memory or CPU.
- Read STAT and tell a healthy sleeper (S) from a stuck one (D) or a zombie (Z).
- Walk from any process to its parent with
ps -o ppid= -p <pid>.