A process list with hundreds of rows is useless when you just need to find and kill one runaway PID, and htop makes that fast and safe. You will finish with a repeatable way to search a busy list, follow a process as it moves, and leave the session without changing the machine. The examples match htop 3.3.0 from the installed Ubuntu package htop 3.3.0-4build1.
Allow about ten minutes. You need a terminal and htop installed. Most of this guide needs no elevated privileges.
Warning: do not use sudo just to start htop. Root access can expose more process details, but it also makes destructive actions easier to trigger by accident.
Confirm the binary and version before relying on a key or option. This is read-only and does not need elevated privileges:
$ command -v htop
/usr/bin/htop
$ htop --version
htop 3.3.0
Checkpoint: if the version differs, read that machine's man htop before copying the key bindings below. htop is an interactive ncurses process viewer, so its normal output is a full-screen terminal rather than a line of text.
Use the read-only switch when you are investigating a host and do not want kill or priority controls available:
$ htop --readonly
F10 or q.F1, h or ? for htop's help screen, then return with F10 or the key shown there.The --readonly option disables htop's system and process changing features. It does not make the displayed information private or freeze the processes themselves.
Checkpoint: you should see a process list with a highlighted row and update meters.
When the list is too busy, press F4 or \ and type part of a command line. Filtering is case-insensitive and uses fixed strings, not regular expressions. Press Esc to cancel it.
For a filter you can reproduce every time you start htop, use the command-line form instead:
$ htop --filter=sshd
The screen should contain only processes whose command lines match sshd. Replace that value with a distinctive fragment such as python or nginx. A filter can return no rows, which means no currently displayed command line contains the term, not that the service is stopped.
Several terms can be separated with a literal vertical bar:
$ htop --filter='sshd|nginx'
Because the terms are fixed strings, punctuation in the filter is not regular-expression syntax. Quote the value so the shell does not interpret it.
If you already know the process ID, show just that process or set of processes:
$ htop --pid=PID
PID with one or more, for example htop --pid=1234,5678.Inside htop, press F3 or / to search command lines. The search selects matching rows but does not hide non-matches; press F4 when you need a smaller working list instead.
For a process that changes position as its CPU or memory use changes, press F. Follow mode keeps the selection on that process while the sort order moves it. Any movement key cancels follow mode.
Press F6, < or > to choose a sort field. The common shortcuts are P for processor use, M for memory use, T for time and N for PID. Press I to reverse the current order.
Press F2 or S to open Setup. It lets you add, remove and reorder columns, and the useful distinctions are easy to miss:
CPU% shows a process's use of the core it is running on, so one process can reach 100% on a multi-core host.NCPU% normalises CPU use by the number of CPUs, which is useful when comparing whole-machine load.RES versus VIRT. RES is resident physical memory; VIRT is the process's virtual memory size, not a claim that all of it is resident.Command shows the full command line when available. Press p to toggle full executable paths where htop can read them.Memory sizes use powers of 1024. If no suffix is shown, htop treats the value as KiB. A dash in every row means a column is unsupported or not implemented on this system, not that every process has a zero value.
With a process selected, press l to show open files when lsof is installed, or w to show its command line on a separate screen. Press s to attach strace when it is installed.
Warning: these actions can reveal sensitive paths and arguments, and tracing can affect a live process. Use them only where you are authorised to inspect it.
The EXE column can show whether the executable or a loaded library was replaced or deleted after the process started. Reading it for every process on Linux may require CAP_SYS_PTRACE or root privileges. If the information is missing, do not infer that the process is healthy or unhealthy from that absence alone.
Warning: do not press F9 or k casually. It opens a signal menu, and the chosen signal is sent to the selected process, or to every tagged process. Space tags a process, c tags it and its children, and U clears all tags, so a mistaken tag selection can affect several processes and interrupt a service.
Similarly, F7 and F8 alter process priority, and their autogroup counterparts can alter scheduling behaviour. The usual operating-system permission rules apply, and the superuser can do more. If the only task is observation, start with --readonly and leave these controls unavailable.
When you change Setup, htop writes its configuration on a clean exit. The default path is ~/.config/htop/htoprc; if that does not exist, htop tries /etc/htoprc before its built-in defaults. The HTOPRC environment variable can select another path.
To try a temporary configuration without changing your normal file, point htop at a file under /tmp:
$ HTOPRC=/tmp/htoprc-test htop --readonly
Recovery: exit cleanly if you want that test configuration saved. If you terminate htop with a signal instead, configuration changes are lost, and hand-editing the file is not the supported workflow since Setup writes it.
HTOPRC.