Skip to content

Review Historical Linux Performance with sar

The vmstat, iostat, and pidstat commands are useful while a slowdown is happening. For an issue that occurred overnight or before anyone logged in, sar can show historical system activity—provided the sysstat collector was enabled beforehand.

This guide enables the distribution’s sysstat collection mechanism and shows how to read saved CPU, memory, and device reports. It cannot reconstruct activity from before collection started. Data files are stored locally, so check their retention and access settings on shared systems.


Step 1: Install sysstat and Enable Data Collection

01

Turn On the Distribution's Collector

Setup

Choose your distribution’s tab to install sysstat and enable collection. On Debian and Ubuntu, the package configuration asks whether to turn collection on. Fedora and RHEL packages use a systemd service and may provide collection timers; check the timer list after enabling the service.

Terminal window
sudo apt update
sudo apt install sysstat
sudo dpkg-reconfigure sysstat
# Select Yes to enable system activity data collection.

Step 2: Confirm That Samples Are Being Written

02

Check the Latest Reports and Data Files

Collection Check

Collection is periodic, so give the collector time to write its first sample. Run sar for today’s CPU report and list the common data directories to locate the daily binary files. Depending on the distribution, they are commonly under /var/log/sa or /var/log/sysstat.

Terminal window
sar -u
sudo ls -lh /var/log/sa /var/log/sysstat 2>/dev/null
❯ View Expected Console Output
Linux ... (host) 10/04/2026 _x86_64_ (4 CPU)
12:00:01 AM CPU %user %system %idle
12:10:01 AM all ... ... ...

03

Compare CPU, Memory, and Swap Samples

Trend Review

Use sar -u for CPU activity and sar -r for memory and swap utilization. If a time window is known, add start and end times with -s and -e. Compare several intervals around the symptom instead of relying on the daily average alone.

Terminal window
sar -u -s 02:00:00 -e 04:00:00
sar -r -s 02:00:00 -e 04:00:00
❯ View Expected Console Output
02:10:01 AM all ... %user ... %system ... %iowait ... %idle
02:10:01 AM kbmemfree ... kbavail ... %memused ... kbswpfree ...

Step 4: Inspect Device Activity During the Same Window

04

Look for Historical Disk Activity

I/O Review

Use sar -d to inspect device activity. Device statistics appear only if they were included in collection on your system. If the report says activity is unavailable, review the distribution’s sysstat configuration and collector options; changing those options will affect future samples, not existing data.

Terminal window
sar -d -p -s 02:00:00 -e 04:00:00
❯ View Expected Console Output
02:10:01 AM DEV tps rkB/s wkB/s await %util
02:10:01 AM nvme0n1 ... ... ... ... ...
Linux terminal showing historical CPU, memory, and disk reports from sar

Figure 1: Historical CPU, memory, and device activity reports read with sar.


Step 5: Read a Previous Day and Record Your Findings

05

Compare the Incident Window with a Normal Period

Analysis

Use sar -u -1 for the previous day’s CPU data when the file is available. For an older date or another directory, pass the matching daily file with -f; file names and locations depend on the distribution. Record the host, date, time window, workload, and report options so another administrator can reproduce the comparison.

Terminal window
# Previous day, using the default activity-file location.
sar -u -1
# Explicit file example; replace with the existing file on this host.
sar -r -f /var/log/sa/sa04
❯ View Expected Console Output
Compare the incident interval with a healthy interval from the same host and workload.

See the sysstat project documentation, sar manual, and sadc collector manual for collection behavior and report options.

Comments