Skip to main content

Diagnosing High Server Load: A Practical Guide to top, htop and iostat

  • Saturday, 20th June, 2026
  • 10:00am

“The server is slow” is the most common ticket we see — and in most cases the cause can be found in five minutes with three standard tools. Here is the exact routine our engineers use.

Step 1: Read the load average correctly

uptime
 10:42:01 up 12 days,  3:14,  1 user,  load average: 6.02, 4.11, 1.98

The three numbers are averages over 1, 5 and 15 minutes. Rule of thumb: sustained load higher than your CPU core count means work is queuing. On a 4-vCPU server, a load of 6 means trouble; on a 16-core bare metal machine it's idle chatter. Rising 1-minute vs 15-minute values = the problem is happening now.

Step 2: Find the culprit with htop

apt install htop -y && htop
  • Sort by CPU% (P) or memory (M).
  • Red bars in the CPU meter = kernel/system time — often I/O or interrupt pressure, not your app.
  • A process in state D (uninterruptible sleep) is stuck waiting for disk or network.

Step 3: Check if it's actually the disk

apt install sysstat -y
iostat -xz 2

Watch %util and await. A device pinned at 95–100% util with high await is saturated. On NetVO NVMe storage this is rare — when we see it, the cause is usually a runaway process (log flood, backup job, database without indexes).

Step 4: Memory pressure and the OOM killer

free -h
dmesg -T | grep -i "out of memory"

If the kernel is killing processes, you'll see it in dmesg. Persistent swapping (si/so columns in vmstat 2) slows everything — either trim the workload or upgrade RAM (cloud upgrades are one click and prorated).

Step 5: The usual suspects

  • MySQL/MariaDB eating CPU: enable the slow query log, add missing indexes.
  • PHP-FPM worker storms: cap pm.max_children to fit your RAM.
  • Log floods: du -sh /var/log/* — rotate aggressively.
  • Cron pile-ups: use flock so long jobs never overlap.

When it's none of the above

Open a ticket with the output of uptime, htop (F5 tree view screenshot) and iostat -xz 2 (three samples). That's everything our engineers need for a fast diagnosis — 24/7.

« Back