top can answer three questions fast: is the machine busy, where is memory going, and which process actually deserves your attention? This guide covers all three, then finishes with a one-frame command stable enough to paste into a ticket or a shell check.
Matches procps 4.0.4-4ubuntu3.3 installed here, with the local top(1) manual dated August 2023. Allow about 15 minutes. You need a terminal and an ordinary user account; reading process information needs no elevated privileges. Reach for sudo only when you hit a specific permission problem and understand why the extra visibility is necessary.
Run top without options:
$ top
The screen has a summary area, a column header and a task area. The summary covers uptime, load averages, task states, CPU states, physical memory and swap. The task area typically shows PID, USER, CPU time, memory, state and COMMAND.
Do not treat the first row as a verdict. Load averages are samples over one, five and 15 minutes, while CPU percentages describe only the interval since the last refresh. A high load can mean CPU work, blocked I/O or another resource constraint entirely.
Checkpoint: press h or ? for help, then q to leave. Terminal awkward, or display damaged after a resize? Ctrl-C is also documented as a way to stop top.
top reports system memory in the summary and process memory in the task area, both by default in KiB or scaled equivalents, not decimal kilobytes. In the process list:
RES is the resident portion currently occupying physical memory.SHR is a shared portion of that resident memory.VIRT is the process's in-use or reserved virtual memory.%MEM is resident memory as a share of total physical memory.A large VIRT is not the same as an equal amount of RAM in use. Start with RES when hunting for pressure on physical memory, then check the summary's available memory and swap lines. Shared libraries make per-process values overlap too, so do not add up every RES value and call it total RAM use.
For a quick unit change, press E to cycle summary memory units or e for task-area units. These affect only the current interactive view, though they may get remembered if you save the configuration later.
Use the interactive view to explore. Press P to sort by CPU use, M to sort by memory use, c to switch between program names and full command lines. Command lines can expose arguments, so be careful copying them into tickets or chat: arguments may carry paths, tokens or other sensitive data.
Press H to show individual threads. Without it, the display shows one process-level total rather than each thread separately, which matters when one application runs many worker threads and you are hunting for the busy one.
To focus on one process, start a separate view with a known PID:
$ top -p 12345
Replace 12345 with a real PID. You can give a comma-separated list of up to 20 PIDs, or repeat -p. PID 0 is treated as the running top program's own PID once it has started.
Safety boundary: k can send a signal to a task and r can change its scheduling priority. Both act on running processes. Do not press either while exploring unless you have confirmed the PID, understand the change, and have an actual operational reason to do it. Observation only? Use q, not k.
Interactive output suits a person, not a script. Batch mode prints plain text without accepting keyboard input; add an iteration limit so it exits on its own:
$ top -b -n 1 -w 120 -o %CPU
-b selects batch mode, -n 1 requests one frame, -w 120 fixes the output width, and -o %CPU sorts by that field. This prints a current snapshot and returns to the shell; the exact rows will vary with host and moment.
A safe pattern for a log file:
top -b -n 1 -w 120 -o %CPU > /tmp/top-snapshot.txt
status=$?
if [ "$status" -ne 0 ]; then
printf 'top failed with status %s\n' "$status" >&2
exit "$status"
fi
sed -n '1,18p' /tmp/top-snapshot.txt
This writes only under /tmp. Remove the temporary file once it is no longer useful:
$ rm -- /tmp/top-snapshot.txt
That removal is irreversible for the file, so keep a copy elsewhere first if it might be evidence for an incident. Feeding a long-lived log? Think about whether command-line arguments or usernames should really be retained in it.
To watch one user, use -u for the effective user ID or name, or -U for any matching user ID or name:
$ top -b -n 1 -w 120 -u alice
To inspect a known process instead, use -p as shown earlier. These filters are mutually exclusive, so pick a PID filter or a user filter for one invocation, not both.
Use -O to list field names available on the installed program before choosing a sort field:
$ top -O
That list can be translated by the system's locale. If a scripted command behaves differently on another host, compare top -V, top -O and the installed manual before assuming the field name is portable.
For a faster live view, -d 2 asks for a two-second update interval; fractional seconds work but a negative value does not. A system administrator can also place top in secure mode, restricting changes like delay, killing and renicing for ordinary users.
top can save display choices with the interactive W command. The personal configuration normally lives under the procps directory in $XDG_CONFIG_HOME, or under $HOME/.config when that variable is unset; older installations may still use a legacy $HOME/.toprc. The exact path is reported when W writes the file.
This persistence is a common source of confusion. A remembered sort order, hidden idle tasks, command-line display or memory scale can make two users see entirely different screens. When comparing screenshots or incident notes, record the command-line options and the relevant interactive toggles too. Use W only after checking the current view really is the one you want to keep.
RES and VIRT.P or M, switch command display with c, and leave with q.-b -n 1 and a fixed width.k or r without a confirmed operational need.