High CPU or memory usage: find the cause and fix it
Diagnose a slow Linux or Windows server: read load average, steal time and I/O wait, find the processes using CPU and RAM, handle OOM kills and add swap.
- Intermediate
- 15 min read
- Updated
Tested on: Ubuntu 24.04 LTS, Ubuntu 26.04 LTS, Debian 12, Debian 13, Windows Server 2022, Windows Server 2025
This guide is not available in your language yet, so it is shown in English.
On this page
A slow server is always busy with something: computing, waiting for the disk, swapping memory or waiting for the hypervisor. This guide shows you how to see which one, find the process behind it and fix it. Commands are for Ubuntu and Debian; a Windows section follows.
Before you start
- Log in over SSH, or through the web console if the server is too slow for SSH.
- Note when the slowness happens. A problem at 03:00 every night points to a scheduled job; one at peak hours points to traffic.
Step 1: Get the overview
uptime
nproc
top- Load average (
uptime, three numbers for 1, 5 and 15 minutes): compare it withnproc. Below the CPU count is fine; well above for a long time means tasks are waiting. - In
top, the CPU line shows where time goes:ususer programs,sythe kernel,wawaiting for disks,ststeal time. PressPto sort by CPU andMto sort by memory;qquits.
Read the pattern:
| You see | Likely cause | Go to |
|---|---|---|
High us, one process on top | A busy application or a runaway process | Step 2 |
High wa | Disk-bound work: database, backups, swapping | Step 3 |
High st | The host is busy; your plan's share is not enough | Step 5 |
| Little free memory, swap in use, processes killed | Memory pressure | Step 3 |
Step 2: Find the processes
ps -eo pid,user,%cpu,%mem,etime,cmd --sort=-%cpu | head -n 15
ps -eo pid,user,%cpu,%mem,rss,cmd --sort=-%mem | head -n 15For a service, see its own resource use and logs:
systemctl status nginx
sudo journalctl -u nginx --since "30 minutes ago"Typical fixes:
- A web application under load: caching, fewer or slower PHP-FPM workers so they fit in memory, database indexes for slow queries.
- A stuck job: restart the service with
sudo systemctl restartand the service name, then find out why it hung. - A scheduled job at the wrong time: move backups or reports to quiet hours (
crontab -l,systemctl list-timers). - An unknown process you did not start: do not just kill it. See what to do if your server is hacked.
Step 3: Check memory and swapping
free -h
vmstat 1 10In free -h, the available column is what programs can still use; free being low is normal because Linux uses spare memory as cache. In vmstat, non-zero si and so columns mean the server swaps actively, which makes everything slow.
Check whether the kernel had to kill processes:
sudo journalctl -k | grep -i -E 'out of memory|oom-kill'Pressure stall information shows how long tasks waited for memory or I/O (if your kernel has PSI enabled):
cat /proc/pressure/memory
cat /proc/pressure/ioStep 4: Fix memory problems
Limit the memory of a service
systemd can cap a service so it cannot take the whole server:
sudo systemctl set-property myapp.service MemoryMax=1GReplace myapp.service with the unit name. When the service exceeds the limit, only it is affected.
Add a swap file
Swap does not replace memory, but it gives the server room for short peaks instead of killing processes. On ext4:
sudo fallocate -l 2G /swapfile
sudo chmod 600 /swapfile
sudo mkswap /swapfile
sudo swapon /swapfile
echo '/swapfile none swap sw 0 0' | sudo tee -a /etc/fstabVerify: swapon --show lists /swapfile, and free -h shows the swap. On Btrfs, a swap file needs special preparation; check your file system with df -T / first.
Step 5: When the plan is the limit
If your applications are tuned and the server still runs out of CPU or memory at normal load, or steal time stays high at your busy hours, the workload has outgrown the plan. Move to a bigger plan or line: upgrade or downgrade a service and VPS vs VDS vs dedicated server.
Windows Server
- Task Manager (Ctrl + Shift + Esc) › Processes and Performance; Resource Monitor (
resmon) shows CPU, memory, disk and network per process. - In PowerShell, list the top consumers:
Get-Process | Sort-Object CPU -Descending | Select-Object -First 10 Name, Id, CPU, WorkingSet
Get-Counter '\Processor(_Total)\% Processor Time' -SampleInterval 2 -MaxSamples 5- Check Event Viewer › Windows Logs › System for low-memory warnings (resource exhaustion events).
- Windows Update and Defender scans cause short peaks after restarts; sustained load usually comes from an application or SQL Server.
Troubleshooting
top shows high load but low CPU use. Tasks are waiting for disks (wa) or are stuck in uninterruptible I/O. Check iostat -x 1 5 (package sysstat) and whether the disk is full: disk full.
The server becomes unreachable at peak times. Memory runs out and the OOM killer stops important services. Limit services, add swap or move to a bigger plan.
Load is high every night. Backups, log rotation or updates run at that time. Spread them out.
Next steps
- Website returns errors under load? Website 502, 503 and 504 errors.
- Measure before you upgrade: VPS vs VDS vs dedicated server.
Frequently asked questions
What is a normal load average?
Compare it with the number of CPUs from nproc. A load average below that number means the CPUs keep up; values well above it for long periods mean tasks wait for CPU or for disk.
What does high steal time mean?
The st value in top is time your virtual CPU waited while the host served other machines. Short spikes are normal; steal time that stays high at your busy hours means your workload needs reserved resources, such as a VDS or a dedicated server.
Why are my processes killed suddenly?
The kernel's out-of-memory killer stops a process when memory runs out. journalctl -k shows Out of memory messages with the process it killed. Reduce memory use, limit the service, add swap or move to a larger plan.
Is free memory close to zero a problem?
Not by itself. Linux uses spare memory as cache and gives it back when programs need it. Look at the available column in free -h instead.
Could high CPU be malware?
Yes. An unknown process using all CPU, often with a random name, can be a crypto miner after a break-in. Follow our guide for compromised servers rather than just killing the process.