ps vs top vs htop: Monitoring Linux Processes
Every Linux system administrator needs to answer the same questions regularly: what is running, what is consuming resources, and why is the system slow? Three tools handle this: ps for snapshots and scripting, top for live monitoring without extras, and htop for an improved interactive experience.
ps: the snapshot tool
ps (process status) takes a snapshot of the process table and prints it. The output is static text, which means you can pipe, grep, sort, and script it. ps is available on every Unix and Linux system without installation.
Common ps invocations
# Every process, user-oriented format (the most common form)
ps aux
# Every process, full format (shows PPID and start time)
ps -ef
# Every process, both BSD and POSIX flags (very verbose)
ps auxf # f adds the process tree (forest)
# Show specific columns only
ps -eo pid,ppid,user,ni,stat,comm
ps -eo pid,%cpu,%mem,vsz,rss,comm --sort=-%cpu
# Show a specific process
ps -p 1234
ps -p 1234 -o pid,comm,%cpu,%mem,etime
# Show all processes owned by a user
ps -u alice
ps -U alice # real UID, not effective UID
# Show processes in a specific group
ps -g groupname
# Show processes belonging to a session
ps -s 1234
Understanding ps output columns
USER -- user that owns the process
PID -- process ID
%CPU -- CPU usage (average since the process started)
%MEM -- percentage of physical RAM in use
VSZ -- virtual memory size in kilobytes
RSS -- resident set size (actual RAM used), in kilobytes
TTY -- controlling terminal (? means none)
STAT -- process state (R/S/D/Z/T plus modifiers)
START -- time the process started
TIME -- cumulative CPU time used
COMMAND -- command name and arguments
Sorting and filtering with ps
# Top 10 CPU consumers
ps aux --sort=-%cpu | head -11
# Top 10 memory consumers
ps aux --sort=-%mem | head -11
# Find a process by name (without grep appearing in the output)
ps aux | grep '[n]ginx'
pgrep -a nginx # cleaner alternative
# Show the process tree
ps axjf
ps --forest -eo pid,ppid,comm
# Watch ps output update (poor man's top)
watch -n 2 'ps aux --sort=-%cpu | head -20'
Custom ps output formats
# Process start time, runtime, PID, command
ps -eo pid,lstart,etime,comm | grep nginx
# Show open file count per process
ps -eo pid,comm --no-headers | while read pid comm; do
echo "$pid $comm $(ls /proc/$pid/fd 2>/dev/null | wc -l) fds"
done | sort -k3 -rn | head -10
# Show environment variables for a process
ps ewww -p 1234
# Show threads within a process
ps -eLf | grep nginx
ps -p 1234 -L
top: live monitoring
top is the traditional live process viewer. It updates every 3 seconds by default and shows the processes consuming the most CPU at the top. Every Linux system has it installed.
Reading the top header
top - 14:23:01 up 12 days, 3:42, 2 users, load average: 0.52, 0.48, 0.45
Tasks: 203 total, 1 running, 202 sleeping, 0 stopped, 0 zombie
%Cpu(s): 2.3 us, 0.8 sy, 0.0 ni, 96.5 id, 0.4 wa, 0.0 hi, 0.0 si, 0.0 st
MiB Mem : 15,879 total, 6,234 free, 5,412 used, 4,233 buff/cache
MiB Swap: 2,048 total, 2,048 free, 0 used. 9,891 avail Mem
The CPU line breaks down time by type:
us: user space (your applications)sy: kernel (system calls, kernel threads)ni: nice (processes running at altered priority)id: idlewa: waiting for I/O (high wa means disk/network is the bottleneck)hi: hardware interruptssi: software interruptsst: steal time (CPU taken by the hypervisor on virtual machines)
Essential top keyboard shortcuts
# Sorting
P sort by CPU usage (default)
M sort by memory usage
N sort by PID
T sort by cumulative CPU time
R reverse sort order
# Display
1 toggle: show per-CPU stats vs aggregate
H toggle: show threads as individual entries
V toggle: tree view (forest)
c toggle: full command line vs just command name
i toggle: hide idle processes
u filter: show only processes for a specific user (prompts for username)
o filter: add a filter condition (e.g., COMMAND=nginx)
# Process management
k kill: prompts for PID then signal
r renice: change nice value of a process
# Output
W write current config to ~/.toprc (persists settings)
q quit
top command-line options
# Set refresh interval to 1 second
top -d 1
# Show only a specific user's processes
top -u alice
# Start top in batch mode (non-interactive, good for scripts)
top -b -n 1 # one iteration, then exit
top -b -n 5 -d 2 # 5 iterations, 2 seconds apart
# Show only a specific number of processes
top -b -n 1 | head -20
# Monitor specific PIDs
top -p 1234,5678,9012
Using top output in scripts
# Get the top 5 CPU-consuming processes right now
top -b -n 1 | grep -A 10 'PID' | tail -5
# Check if a process is using more than 50% CPU
top -b -n 1 -p $(pgrep nginx | head -1) | awk 'NR>7 {if ($9 > 50) print "HIGH CPU: "$9"%"}'
# Log resource usage every minute
while true; do
top -b -n 1 | head -20 >> /var/log/resource-usage.log
sleep 60
done
htop: the enhanced alternative
htop provides everything top does with a more readable interface: colour-coded output, per-CPU and per-memory bar graphs, mouse support, and a more intuitive process management workflow. It is not always installed by default but is available in every major distribution’s repositories.
# Install htop
sudo apt install htop # Debian/Ubuntu
sudo dnf install htop # Fedora/RHEL
sudo pacman -S htop # Arch
sudo zypper in htop # openSUSE
Reading the htop header
At the top, htop shows:
- A bar graph for each CPU core (colour-coded: green=user, blue=low priority, red=kernel, yellow=IRQ)
- Memory and swap bar graphs
- Load average, uptime, task counts
This gives an immediate visual overview that top’s text output does not match.
Essential htop keyboard shortcuts
# Navigation
Arrow keys move cursor up/down through process list
PgUp/PgDn scroll the process list quickly
Home/End jump to first/last process
# Sorting
F6 or > open sort column selection menu
P sort by CPU
M sort by memory
T sort by time
Click header sort by that column (mouse)
# Filtering and search
F3 or / incremental search (type to filter by name)
F4 filter: keep only matching processes visible
u show only processes for a selected user
# Display modes
F5 or t toggle tree view (show process hierarchy)
H toggle: show/hide user threads
K toggle: show/hide kernel threads
1 toggle: show per-CPU bar graphs vs compressed view
# Process management
F9 or k send signal (opens signal selection menu)
F7 or ] increase priority (lower nice value, root only)
F8 or [ decrease priority (raise nice value)
F2 open setup/configuration screen
# Other
F1 help screen
q or F10 quit
htop command-line options
# Sort by a specific column on startup
htop --sort-key=PERCENT_CPU
htop --sort-key=PERCENT_MEM
htop --sort-key=PID
# Show only a specific user's processes
htop -u alice
# Set refresh delay in tenths of a second
htop -d 20 # refresh every 2 seconds
# Monitor specific PIDs
htop -p 1234,5678
# Start in tree mode
htop -t
Configuring htop
Press F2 to open the setup screen. Useful configurations:
- Display options: show threads, show custom header columns
- Columns: add or remove columns from the process list (context switches, page faults, I/O rates)
- Colors: choose a colour scheme
- Meters: customise what appears in the header (add network I/O, disk I/O meters)
Settings are saved to ~/.config/htop/htoprc.
Choosing the right tool
Use ps when:
- You are writing a script
- You want to pipe output to grep, awk, or sort
- You need custom column formatting
- You want a one-time snapshot, not a live view
Use top when:
- You need to check resource usage quickly on any system (it is always installed)
- You want to see what is consuming CPU right now
- You need batch output for logging
Use htop when:
- You want the most comfortable interactive experience
- You need to navigate, filter, and manage processes easily
- You want to see per-CPU graphs and a tree view without extra key presses
- You have it installed (or can install it)
Other process monitoring tools
# atop: records system activity for historical analysis
sudo apt install atop
atop -r /var/log/atop/atop_$(date +%Y%m%d) # read historical data
# glances: broader system overview (network, disk, sensors)
sudo apt install glances
glances
# iotop: processes sorted by disk I/O
sudo apt install iotop
sudo iotop
# nethogs: processes sorted by network I/O
sudo apt install nethogs
sudo nethogs
# pidstat: per-process CPU, memory, I/O over time
sudo apt install sysstat
pidstat 1 10 # 10 snapshots, 1 second apart
# nmon: comprehensive system monitor
sudo apt install nmon
nmon
For CPU diagnostics, top -b -n 1 | head -20 is often all you need. For memory pressure, ps aux --sort=-%mem | head -10 finds the culprit. For interactive investigation, htop -t with tree view gives the clearest picture of what is running and why.
Frequently Asked Questions
What is the difference between ps, top, and htop?
ps takes a snapshot of processes at the moment you run it and outputs the result as text you can pipe and filter. top is a live, auto-refreshing display of the most resource-intensive processes, updated every few seconds. htop is an enhanced version of top with a colour display, mouse support, and easier interaction — it shows more information by default and lets you sort, filter, and kill processes interactively. For scripting, use ps. For quick real-time monitoring, use top or htop.
What does ps aux mean?
ps aux lists all running processes on the system. a shows processes from all users (not just your own), u shows the output in user-oriented format with columns for CPU, memory, and the owning user, and x includes processes that have no controlling terminal (daemons and background services). Together, ps aux gives a complete snapshot of every process running on the system at that moment.
How do I find which process is using the most CPU or memory?
In ps, use ps aux —sort=-%cpu | head -10 for the top CPU consumers and ps aux —sort=-%mem | head -10 for memory. In top, press P to sort by CPU (default) and M to sort by memory. In htop, click the column header to sort by it, or press F6 to select a sort column from a menu. In htop, CPU and memory usage are also shown as bar graphs at the top of the screen for an at-a-glance overview.
How do I kill a process from top or htop?
In top, press k, then enter the PID of the process to kill, then enter the signal number (15 for SIGTERM, 9 for SIGKILL). In htop, navigate to the process using the arrow keys and press F9 (or just press k) to open a signal selection menu. Select the signal and press Enter. htop is much more convenient for this because you do not need to look up the PID separately — you navigate directly to the process you want.
What is load average in top and htop?
Load average is the average number of processes waiting for CPU time (or doing uninterruptible I/O) over the last 1, 5, and 15 minutes. A load average equal to the number of CPU cores means the system is fully utilised. A load average below the core count means headroom is available. A load average significantly above the core count means processes are queuing for CPU time and the system is overloaded. On a 4-core machine, a load of 4.0 is fully utilised; a load of 8.0 means significant contention.