Home / Alt manpages / prtstat(1)

  • prtstat(1)
  • User command
  • linux

Read Process Statistics Safely with prtstat

You will finish with a small, repeatable way to inspect one Linux process, save either a readable report or the command's raw fields, and recognise when a PID has disappeared. The examples use prtstat from psmisc 23.7, the version installed on this machine.

Allow about ten minutes. You need a shell and a process ID that you are allowed to inspect. The normal examples are unprivileged and read-only. This guide does not stop, reprioritise or otherwise alter a process.

1. Check the installed command

Confirm which binary your shell will run and check its version:

$ command -v prtstat
/usr/bin/prtstat
$ prtstat --version
prtstat (PSmisc) 23.7

The manual gives two forms: prtstat [ -r | --raw ] pid for a report, and prtstat -V or prtstat --version for version information. It has no option for selecting several PIDs at once. Inspect one PID per invocation.

Checkpoint

If command -v finds nothing, install psmisc through your normal distribution process. Do not copy an output example and assume it proves that your host has the same package version.

2. Choose a live PID without changing it

For a quick test, ask the shell for its own process ID:

$ printf 'shell PID: %s\n' "$$"
shell PID: 646404

Your number will differ. For a named process, use a read-only listing and then choose an exact PID:

$ ps -eo pid,comm,args | rg '[s]sh|[n]ginx|[s]ystemd'
      1 systemd         /sbin/init
   2187 sshd            sshd: user@pts/2

Do not select a PID from a partial name match without checking the command and arguments. A PID is a short-lived identifier, not a permanent identity. A service can exit after the listing and before prtstat reads it, or the kernel can later reuse the number for another process.

If the process belongs to another account, the kernel's /proc permissions may prevent inspection. Try the ordinary command first. Only use an elevated shell when your host policy allows it and you genuinely need to inspect that process; sudo does not make a stale PID current.

3. Produce the readable report

Pass the PID as the final argument. This reads the process statistics from /proc/<pid>/stat and formats them for a person:

$ prtstat "$$"
Process: bash             State: S (sleeping)
CPU#:  2                 TTY: 0:0        Threads: 1
Process, Group and Session IDs
 Process ID: 646404       Parent ID: 639163
 Group ID: 646404         Session ID: 646404
 T Group ID: -1

Page Faults
 This Process   (minor major):      899         0
 Child Processes (minor major):    1024         0

CPU Times
 This Process (user system guest blkio): 0.00   0.00   0.00
 Child processes (user system guest):     0.01   0.00   0.00

The exact numbers and some labels depend on the process and the moment of the read. The useful first checks are the command name, state, process ID, parent ID, group and session IDs, page faults, CPU times, memory and scheduling values. A single report is a snapshot, not a live monitor.

Checkpoint

Make sure the reported Process ID is the PID you requested and that the command name is the process you intended. If either is wrong, stop and reselect the PID before interpreting the rest.

4. Save a report for later comparison

Redirect the readable form to a new file when you need a ticket attachment or a before-and-after comparison:

$ pid="$$"
$ prtstat "$pid" > "prtstat-$pid.txt"
$ test -s "prtstat-$pid.txt" && echo "saved prtstat-$pid.txt"
saved prtstat-646404.txt

The command writes the report to standard output, so shell redirection controls the destination. The test -s check confirms that the file exists and is non-empty. It does not confirm that the process stayed the same after the read. If a destination already contains evidence, choose a new name or make a deliberate backup before using >, because redirection truncates an existing file.

There is no state to undo in prtstat itself. To remove a report you created, first check its exact path and contents, then remove that file only when you no longer need it. Keep diagnostic files if they may be part of an incident record.

5. Use raw output when a script needs the fields

Add --raw, or its short form -r, when you need the values close to the underlying /proc/<pid>/stat record:

$ prtstat --raw "$$"
         pid: 646404           comm: bash
       state: S               ppid: 639163
        pgrp: 646404        session: 646404
       tty_nr: 0              tpgid: -1
        flags: 400000          minflt: 925
       cminflt: 1131           majflt: 0
       cmajflt: 0              utime: 0
        stime: 0              cutime: 1
        cstime: 0           priority: 20

Raw mode is still formatted text. It is easier to compare in a terminal or preserve in a diagnostic file, but do not treat the spacing as a stable machine-readable interface unless your own parser deliberately handles it. The process can change between two invocations, and counters can increase while it runs.

For a quick status check, test the exit code as well as the output:

$ if prtstat --raw "$pid" > "raw-$pid.txt"; then
>     echo "prtstat succeeded"
> else
>     echo "prtstat could not read PID $pid" >&2
> fi
prtstat succeeded

6. Handle a missing or changing PID

A process may exit before the command opens its proc entry. For example:

$ prtstat 99999999
Process with pid 99999999 does not exist.

This is a failed inspection, not evidence that the process was healthy or unhealthy. Check the original service or application logs, obtain a fresh PID, and run the command again. If you are investigating a short-lived process, capture the PID and report from the same supervising script as close together as possible, while accepting that a race remains.

A successful report also has limits. It does not freeze the process, sample it repeatedly, explain why it is blocked, or prove that a service is functioning. Use a purpose-built monitor, tracing tool or service diagnostic for those questions. Keep prtstat as the quick snapshot that tells you what the kernel reported for one PID at one point in time.

Done means

  • You confirmed the installed psmisc version and selected a live PID deliberately.
  • You can read the normal report's identity, state, resource and scheduling sections.
  • You know that --raw exposes formatted fields derived from /proc/<pid>/stat.
  • You checked both output and exit status when saving a report.
  • You treat a missing PID as a race or stale identifier, not as a diagnosis.
  • You did not modify, stop or reprioritise the inspected process.