Linux Out of Memory (OOM): Find the Killer, Fix and Prevent Recurrence

linux out of memory - custom-oom-featured.png

When the kernel runs out of RAM and swap, the OOM killer terminates a process to keep the system alive. Symptoms include random service deaths, SSH lag, and
Killed in logs without a clean application stack trace.

Start with htop and free and
swap if you need short-term headroom while you fix the leak.

What OOM Looks Like

Apps disappear, load spikes, database connections drop. The kernel log names the victim process.

OOM killer
kernel action

Check Memory Now

Use available in free -h; watch swap I/O.

bashsnapshot
free -h
swapon --show
free -h
available

Find the Memory Hog

Sort processes by RSS before and during incidents.

bashtop memory
ps aux --sort=-%mem | head -15
htop / ps
top consumers

Read OOM Killer Lines

Kernel messages include the score and chosen PID.

bashkernel log
sudo dmesg -T | grep -i 'out of memory\|Killed process' | tail -20
sudo journalctl -k --since today | grep -i oom
dmesg / journal
Killed process

Limits with systemd and ulimit

Cap runaway services with MemoryMax= so one unit cannot take the whole box.

iniunit drop-in
[Service]
MemoryMax=2G
MemoryMax
cgroups

Short-Term Relief vs Real Fix

Restarting frees RAM; adding swap buys time; adding RAM or fixing the leak solves it.

mitigations
restart vs fix

Prevent Next Time

Alert on memory percentage; graph trends in Prometheus/Grafana if you have it.

WarningDisabling the OOM killer is almost never appropriate on production servers.
monitoring
alerts

Quick Reference

  • Grep Killed process in dmesg / journalctl -k
  • ps aux --sort=-%mem for suspects
  • MemoryMax= on heavy systemd services

Related tutorials

Diagrams are original illustrations by Gnome IT Solutions. Tutorial text © Gnome IT Solutions.