Review Historical Linux Performance with sar
The vmstat, iostat, and pidstat commands are useful while a slowdown is happening. For an issue that occurred overnight or before anyone logged in, sar can show historical system activity—provided the sysstat collector was enabled beforehand.
This guide enables the distribution’s sysstat collection mechanism and shows how to read saved CPU, memory, and device reports. It cannot reconstruct activity from before collection started. Data files are stored locally, so check their retention and access settings on shared systems.
Step 1: Install sysstat and Enable Data Collection
Turn On the Distribution's Collector
SetupChoose your distribution’s tab to install sysstat and enable collection. On Debian and Ubuntu, the package configuration asks whether to turn collection on. Fedora and RHEL packages use a systemd service and may provide collection timers; check the timer list after enabling the service.
sudo apt updatesudo apt install sysstatsudo dpkg-reconfigure sysstat# Select Yes to enable system activity data collection.sudo dnf install sysstatsudo systemctl enable --now sysstatsystemctl list-timers 'sysstat*'Step 2: Confirm That Samples Are Being Written
Check the Latest Reports and Data Files
Collection CheckCollection is periodic, so give the collector time to write its first sample. Run sar for today’s CPU report and list the common data directories to locate the daily binary files. Depending on the distribution, they are commonly under /var/log/sa or /var/log/sysstat.
sar -usudo ls -lh /var/log/sa /var/log/sysstat 2>/dev/null❯ View Expected Console Output
Linux ... (host) 10/04/2026 _x86_64_ (4 CPU)
12:00:01 AM CPU %user %system %idle12:10:01 AM all ... ... ...Step 3: Review CPU and Memory Trends
Compare CPU, Memory, and Swap Samples
Trend ReviewUse sar -u for CPU activity and sar -r for memory and swap utilization. If a time window is known, add start and end times with -s and -e. Compare several intervals around the symptom instead of relying on the daily average alone.
sar -u -s 02:00:00 -e 04:00:00sar -r -s 02:00:00 -e 04:00:00❯ View Expected Console Output
02:10:01 AM all ... %user ... %system ... %iowait ... %idle02:10:01 AM kbmemfree ... kbavail ... %memused ... kbswpfree ...Step 4: Inspect Device Activity During the Same Window
Look for Historical Disk Activity
I/O ReviewUse sar -d to inspect device activity. Device statistics appear only if they were included in collection on your system. If the report says activity is unavailable, review the distribution’s sysstat configuration and collector options; changing those options will affect future samples, not existing data.
sar -d -p -s 02:00:00 -e 04:00:00❯ View Expected Console Output
02:10:01 AM DEV tps rkB/s wkB/s await %util02:10:01 AM nvme0n1 ... ... ... ... ...
Figure 1: Historical CPU, memory, and device activity reports read with sar.
Step 5: Read a Previous Day and Record Your Findings
Compare the Incident Window with a Normal Period
AnalysisUse sar -u -1 for the previous day’s CPU data when the file is available. For an older date or another directory, pass the matching daily file with -f; file names and locations depend on the distribution. Record the host, date, time window, workload, and report options so another administrator can reproduce the comparison.
# Previous day, using the default activity-file location.sar -u -1
# Explicit file example; replace with the existing file on this host.sar -r -f /var/log/sa/sa04❯ View Expected Console Output
Compare the incident interval with a healthy interval from the same host and workload.See the sysstat project documentation, sar manual, and sadc collector manual for collection behavior and report options.