Home / Alt manpages / sadc(8)

  • sadc(8)
  • Admin command
  • linux

Collect Short, Readable Samples with sadc

By the end of this guide you will have a bounded binary activity file that sar can read. You will also know how to add optional metrics, protect a file from competing collectors, and avoid accidentally replacing a system activity archive.

Before you start

This guide targets the sadc supplied by Debian's sysstat package version 12.6.1-2. The installed binary is /usr/lib/sysstat/sadc; it is not on this machine's ordinary command search path. The manpage is dated July 2020, so treat the local binary and its documentation as the authority when another system has a different sysstat release.

You need sar from the same sysstat installation for the inspection steps. A three-sample run takes roughly five seconds because the first sample is followed by two one-second intervals. Writing under /tmp needs no elevated privileges. Writing the conventional files under /var/log/sysstat normally does, so use sudo only for that operational case.

Checkpoint 1: confirm the binary

  1. Check the installed version and path.
/usr/lib/sysstat/sadc -V
command -v sar

The first command reports sysstat version 12.6.1 on the reference machine. The version output is useful when comparing data files: the manpage warns that old files can have an incompatible format. If the path does not exist, install or enable the distribution's sysstat package according to its normal administration process. Do not substitute a similarly named collector without checking its documentation.

Checkpoint 2: collect a bounded file

  1. Write three one-second records to a new temporary file.
sample_file=$(mktemp /tmp/sadc-sample.XXXXXX)
/usr/lib/sysstat/sadc 1 3 "$sample_file"
printf 'Collected: %s\n' "$sample_file"

The positional arguments are interval, count, and outfile. Here, 1 3 asks for three records at one-second intervals. The output is binary, not a text report, so do not open it in an editor or expect useful output from cat. A successful run normally prints nothing from sadc itself.

Inspect the result through sar:

/usr/bin/sar -f "$sample_file"

You should see a host and kernel line, a CPU table with headings such as %user, %system and %idle, three timestamped rows, and an Average: row. The exact numbers depend on the host. If the file is empty or sar rejects it, check the error text, confirm that /proc is mounted, and verify that both programs come from compatible sysstat versions.

Checkpoint 3: collect optional activities deliberately

sadc collects most kernel data by default, but some activities are optional to control file growth. For a short diagnostic capture, request disk, interrupt, IPv6, power and SNMP statistics explicitly:

metrics_file=$(mktemp /tmp/sadc-metrics.XXXXXX)
/usr/lib/sysstat/sadc -S DISK,INT,IPV6,POWER,SNMP 1 3 "$metrics_file"
/usr/bin/sar -f "$metrics_file"

ALL selects those optional keywords. XDISK extends disk collection with partition and filesystem statistics on kernels 2.6.25 and later. XALL selects all listed activities and their extensions. Availability still depends on the kernel and exposed interfaces, so an option does not guarantee that every metric exists.

There is a subtle file rule: when appending to an existing data file, the activities already stored in that file take precedence over a new -S selection. If a capture needs a different metric set, start a new file rather than assuming that a later command changes the old file's format.

Checkpoint 4: prevent competing writers

Scheduled collectors can overlap when a slow run is still active as the next cron invocation starts. Add -L when more than one process could write the same file:

/usr/lib/sysstat/sadc -L 1 3 "$sample_file"

The option asks for an exclusive lock before writing or truncating. A lock failure is fatal for setup records, while a normal record to an existing file can be retried at the next interval. This reduces the chance of a corrupted activity file, but it does not make two independently chosen output filenames equivalent. Coordinate the filename as well as enabling the lock.

Use the daily archive only when you mean it

Passing - as the output file selects the standard daily file under /var/log/sysstat. Its default name is saDD, where DD is the day of the month. Add -D to use the unambiguous saYYYYMMDD form. An output directory is treated as an alternate directory for that standard file.

These paths are shared operational data, not scratch space. Check the target before using elevated privileges:

sudo install -d -m 0755 /var/log/sysstat
sudo /usr/lib/sysstat/sadc -D -L 60 10 -

The command records ten samples, one minute apart, in today's dated archive. The first line changes state in a system-owned directory and the collection runs for about nine minutes after its initial sample. Stop before running it if that duration is not acceptable.

Warning

Do not use -F casually. It forces creation and can truncate an existing file when its format is unknown to the current sadc. If an archive is damaged or must be replaced, preserve a copy first, record the package version, and follow the site's backup procedure. Recovery from truncation requires restoring that backup; there is no sadc undo command.

Add a startup or backup marker

Without an interval and count, -C writes a dummy record containing a comment. This is useful for marking an event in a file that sar will later display:

marker_file=$(mktemp /tmp/sadc-marker.XXXXXX)
/usr/lib/sysstat/sadc -C 'Backup Start' "$marker_file"
/usr/bin/sar -C -f "$marker_file"

The report includes a COM row with the comment. Do not confuse this marker command with continuous collection: because no interval or count is supplied, it writes the marker and exits. A plain startup mark can be written to the daily file with /usr/lib/sysstat/sadc -, but that changes shared state and is usually best left to the distribution's sysstat integration.

Time and durability choices

Use -f when a reset must be less likely to leave recently collected data only in the filesystem cache. It calls fdatasync(), which can slow collection because the process waits for the underlying disk. It is a durability trade-off, not a replacement for backups.

By default timestamps use local time. Set S_TIME_DEF_TIME=UTC for a UTC data file and for UTC selection of the daily archive. Keep this choice consistent when comparing files from several hosts; otherwise a correct sample can appear to be at the wrong wall-clock time.

Done means

  • sadc -V identifies the installed sysstat release.
  • A bounded run has a new binary file and sar -f reads it.
  • Optional metrics were selected when needed, and a new file was used for a new selection.
  • Shared output has a deliberate filename, suitable permissions, and -L where writers may overlap.
  • No daily archive was forced or truncated without a backup and a recovery plan.