vmstat Explained
vmstat gives a compact, line-per-sample view of what the whole system is doing: how many processes are competing for the CPU, how memory and swap are being used, how much I/O is happening, and how CPU time is split between real work, I/O waits, and idle time. It’s one of the oldest Unix monitoring tools and remains one of the fastest ways to get an overview without launching a full-screen interface.
Basic Usage
vmstat 1 5
This samples every 1 second, 5 times, then stops. Without arguments, vmstat prints a single summary line (averaged since boot) and exits immediately.
Example output:
procs -----------memory---------- ---swap-- -----io---- -system-- ------cpu-----
r b swpd free buff cache si so bi bo in cs us sy id wa st
2 0 0 2156480 143220 8734512 0 0 45 62 891 1523 12 4 83 1 0
1 0 0 2148300 143220 8735100 0 0 0 18 845 1401 8 3 89 0 0
Important: Ignore the First Line
The very first line vmstat prints is a summary averaged since system boot, not a live sample. If you’ve been running for weeks, that first line can show numbers that don’t reflect current conditions at all. Every line after the first reflects the actual sampling interval. Always skip line one when reading output.
The procs Columns
| Column | Meaning |
|---|---|
r | Processes currently running or waiting for CPU time (run queue length) |
b | Processes blocked, waiting on I/O (uninterruptible sleep) |
If r is consistently higher than your CPU core count, processes are queuing for CPU time. A high b value means processes are stuck waiting on disk or network I/O rather than CPU.
The memory Columns
| Column | Meaning |
|---|---|
swpd | Amount of virtual memory currently swapped out |
free | Idle memory, same concept as free’s “free” column |
buff | Memory used as buffers |
cache | Memory used as page cache |
These map closely to the columns in the free command, just reported in KiB by default.
The swap Columns
| Column | Meaning |
|---|---|
si | Memory swapped in from disk, in KB/s |
so | Memory swapped out to disk, in KB/s |
Non-zero, sustained values here, especially in so, mean the system is actively using swap and paying a real performance penalty for it. Occasional small blips are normal; a steady stream of activity is not.
The io Columns
| Column | Meaning |
|---|---|
bi | Blocks received from a block device (reads), per second |
bo | Blocks sent to a block device (writes), per second |
These give a rough sense of disk activity volume. For a per-device breakdown, pair vmstat with iostat.
The system Columns
| Column | Meaning |
|---|---|
in | Interrupts per second |
cs | Context switches per second |
A very high cs value can indicate excessive process or thread switching overhead, sometimes seen with poorly tuned high-concurrency workloads.
The cpu Columns
| Column | Meaning |
|---|---|
us | Time spent running user-space (application) code |
sy | Time spent running kernel (system) code |
id | Idle time |
wa | Time spent waiting on I/O with runnable work available |
st | Time stolen by a hypervisor, on virtualized systems |
A high wa percentage means the CPU had work ready to run but was stalled waiting for disk or network, pointing toward a storage bottleneck rather than a CPU one. A non-zero st on a VM means other tenants on the same physical host are competing for CPU time.
Practical Reading Order
When triaging a slow system with vmstat 1, a reasonable order is: check r against core count for CPU contention, check so/si for swap activity, check wa for I/O stalls, and check cs for excessive context switching. Combined with top/htop for per-process detail and iostat for per-device I/O, this covers most performance triage needs without extra tooling.
Frequently Asked Questions
What does vmstat stand for and what does it show?
vmstat stands for virtual memory statistics. It reports a single-line snapshot covering process counts (running and blocked), memory usage, swap activity, block I/O, interrupts and context switches, and CPU time breakdown, all in one compact table. Run with an interval and count, like vmstat 1 5, it samples repeatedly, making it useful for watching trends rather than a single point-in-time reading.
Why is the first line of vmstat output different from the rest?
The first line vmstat prints is an average since boot, not a live sample, which makes it misleading if read as current activity. Every subsequent line reflects the actual interval between samples. When reading vmstat output, always discard the first line and focus on the second line onward.
What does the r column mean in vmstat?
The r column shows the number of processes currently running or waiting for CPU time, effectively the run queue length. If r is consistently higher than the number of CPU cores on the system, processes are queuing for CPU time, indicating CPU contention. An r value at or below the core count generally means the CPU is keeping up with demand.
What do the si and so columns in vmstat mean?
si is the rate of memory being swapped in from disk, and so is the rate being swapped out to disk, both measured in kilobytes per second. Sustained non-zero values in either column, especially so, indicate the system is actively using swap under memory pressure, which typically comes with a noticeable performance penalty since disk is far slower than RAM.
What does the wa column under cpu mean in vmstat?
wa is the percentage of CPU time spent waiting on I/O, meaning the CPU had runnable work available but was idle because it was waiting for a disk or network operation to complete. A high wa percentage points to a storage or I/O bottleneck rather than a CPU bottleneck, and pairs well with iostat for identifying which device is responsible.
How is vmstat different from top or htop?
top and htop are interactive, full-screen tools focused on per-process resource usage, refreshing the whole display each interval. vmstat is a lightweight, scriptable command that prints one line per sample to standard output, making it easy to log, pipe, or parse in scripts and over SSH connections with limited bandwidth. vmstat also surfaces some system-wide metrics, like swap rates and interrupt counts, that top does not show directly.