vmstat and iostat on Linux: CPU, Memory, Swap and Disk Bottlenecks

vmstat iostat linux - custom-vms-featured.png

When htop shows something odd, vmstat and iostat give a compact time series you can log during an incident.

Install sysstat if iostat is missing. Pair disk findings with
df/du/ncdu when space is tight but I/O is the symptom.

Two Complementary Tools

vmstat summarises CPU, memory, and block I/O. iostat breaks out per-disk throughput and latency.

bashinstall sysstat (Debian/RHEL)
sudo apt install -y sysstat    # or: sudo dnf install -y sysstat
vmstat vs iostat
system vs disk

vmstat Header and Process Columns

r is runnable tasks; b is uninterruptible sleep (often I/O). Sustained high b warrants disk investigation.

bashsample
vmstat 1 5
r and b
run queue

CPU Line: us, sy, wa

High wa (iowait) means CPUs are waiting on disk. High sy can mean excessive syscalls or drivers.

bashwatch CPU
vmstat 1 | awk '{print $13,$14,$16}'  # us sy wa on some layouts — read header row
CPU breakdown
watch wa

Memory and Swap Columns

si and so show swap pages moving in and out. Non-zero sustained values hurt latency.

bashwith swap
free -h; vmstat 1 10
swap si/so
memory pressure

iostat for Disk Saturation

%util near 100% means the device is busy. await is average wait time per I/O request.

bashdisks
iostat -xz 1 5
iostat -xz
util and await

Log a Short Sample During Incidents

Capture 30–60 seconds while users complain; compare to a quiet baseline.

bashsave sample
vmstat 1 30 | tee /tmp/vmstat-$(date +%F-%H%M).log
sampling
vmstat 1 N

Translate Numbers Into Actions

High wa → disk or NFS. si/so → RAM or swap tuning. Load without wa → CPU-bound workload.

TipOn cloud VMs, also check provider metrics for volume throttling.
next steps
disk vs CPU vs RAM

Quick Reference

  • vmstat 1 10 — quick CPU/mem/swap series
  • High wa → disk; si/so → swap pressure
  • iostat -xz 1 for per-disk %util

Related tutorials

Diagrams are original illustrations by Gnome IT Solutions. Tutorial text © Gnome IT Solutions.