Home / Alt manpages / sadf(1)

  • sadf(1)
  • User command
  • linux

Turn sysstat Data into JSON and CSV with sadf

You will finish with repeatable commands for extracting historical system-activity data as JSON or semicolon-separated records, ready for a script or database import. The examples use sadf from sysstat 12.6.1, installed here as package version 12.6.1-2.

Allow about fifteen minutes. You need a shell and a readable sysstat data file, normally under /var/log/sysstat. Every command in this guide only reads an existing file and writes to standard output. No elevated privileges are normally needed. Do not use sudo just because the data directory is owned by root; first test whether your account can read the chosen file.

1. Confirm the installed command and data file

Check the executable and version before putting an export in a script:

$ command -v sadf
/usr/bin/sadf
$ sadf -V
sysstat version 12.6.1
(C) Sebastien Godard (sysstat <at> orange.fr)

On this host, the current daily file is /var/log/sysstat/sa26. Use the file for the date you actually need; the name is host-specific. The ordinary default is the most recent daily file in /var/log/sysstat, with names such as saDD or saYYYYMMDD. You can also pass a day offset such as -1 for yesterday.

Checkpoint: inspect the file without changing it:

$ test -r /var/log/sysstat/sa26 && echo readable
readable
$ sadf -H /var/log/sysstat/sa26 | head -n 8
System activity data file: /var/log/sysstat/sa26 (0x2175)
File created by sar/sadc from sysstat version 12.6.1
Genuine sa datafile: yes (0)
Host: Linux 6.8.0-139-generic server.dixon.cx	09/26/26
File date: 2026-09-26

The header is useful for confirming the file date, host and creator version. If the file was made by an incompatible sar, stop there and select a compatible data file.

2. Export structured data as JSON

Use -j when a program needs named JSON structures. This example selects a short window to keep the terminal output manageable:

$ sadf -j -s 20:00:00 -e 20:10:00 /var/log/sysstat/sa26 > cpu-window.json
$ head -n 12 cpu-window.json
{"sysstat": {
	"hosts": [
		{
			"nodename": "server.dixon.cx",
			"sysname": "Linux",
			"release": "6.8.0-139-generic",
			"machine": "x86_64",
			"number-of-cpus": 8,
			"file-date": "2026-09-26",

With no activity option, sadf selects CPU activity. The JSON contains the host metadata and the selected statistics. Validate the result with an installed JSON parser when your workflow has one:

$ jq empty cpu-window.json && echo valid-json
valid-json

jq is not part of sadf; if it is absent, use your application's JSON parser instead. An empty time window can still produce valid JSON with no matching records, so validity alone is not a guarantee that the requested interval contained samples.

3. Export database-friendly records

Use -d for records separated by semicolons. Put the file name before the two dashes that introduce options intended for sar:

$ sadf -d -s 20:00:00 -e 20:10:00 /var/log/sysstat/sa26 -- -n DEV > network.csv
$ head -n 5 network.csv
# hostname;interval;timestamp;IFACE;rxpck/s;txpck/s;rxkB/s;txkB/s;rxcmp/s;txcmp/s;rxmcst/s;%ifutil

The output is not comma-separated CSV despite the filename above: -d uses semicolons. The first line is a header beginning with #, followed by the host, interval, timestamp and activity fields. Keep that delimiter in the importer, or choose a name such as network.sadf to make the format obvious.

The -- matters. Without it, a sar activity flag can be mistaken for a sadf option. -n DEV asks for network-device activity; it is not an instruction to discover interfaces or change networking.

4. Bound the records you select

The default time range is narrower than many readers expect: sadf starts at 08:00:00 and ends at 18:00:00 unless you provide -s and -e. Hours use 24-hour notation. Make the range explicit in scheduled exports:

$ sadf -d -s 00:00:00 -e 23:59:59 /var/log/sysstat/sa26 -- -n DEV 60 10

The positional values after the options are interval and count. This asks for ten records at 60-second intervals from the selected file. Omitting count displays all matching records. These values select saved records; they do not make sadf collect fresh samples.

Use -P for processor-specific CPU data. Processor 0 is the first processor, while ALL reports each processor and the global average:

$ sadf -p -P 0 -s 20:00:00 -e 20:10:00 /var/log/sysstat/sa26 | head -n 5

The -p format uses tab-separated fields suited to tools such as awk. It is often easier to process than the human-oriented output from sar.

5. Make timestamps unambiguous

By default, timestamps are UTC. Choose the representation deliberately when data crosses machines:

  • -T displays timestamps in the current machine's local time.
  • -t uses the original local time of the host that created the data file.
  • -U emits UTC seconds since the Unix epoch.

For example, this keeps the record format database-friendly while choosing the creator's local time:

$ sadf -d -t -s 20:00:00 -e 20:10:00 /var/log/sysstat/sa26 -- -n DEV | head -n 3

Do not compare a local-time export with a UTC export as if their text timestamps were interchangeable. Record which option you used alongside the exported file, especially around daylight-saving changes.

6. Handle failures without changing the host

If sadf reports that it cannot open a file, check the path and read permission:

$ ls -l /var/log/sysstat/sa26
$ test -r /var/log/sysstat/sa26 && echo readable || echo not-readable

A non-zero result can also mean that the file was created by an incompatible sysstat version, or that the requested options do not match the data present. Re-run sadf -H and test a short, known interval before changing permissions or copying files. Changing ownership or permissions on system activity logs is a security decision and is outside this workflow.

For a browser-viewable graph, sadf -g DATAFILE > output.svg writes SVG, but do not treat SVG as a data interchange format. Keep it separate from the JSON or semicolon export. If you overwrite an existing output with >, the shell truncates it first; use a new filename and inspect it before replacing a useful report.

Done means

  • You checked the installed sysstat version and selected a compatible data file.
  • Your export states its time range, activity selection and timestamp convention.
  • JSON was written with -j and semicolon-separated records with -d.
  • sar activity options appear after --.
  • You understand that sadf reads saved records and does not collect new samples.
  • No permissions, services or system activity files were changed.