Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Use ps aux to take a one-time snapshot of all processes visible in your current Linux host or PID namespace. Use top for a continuously updating view, pgrep -a process-name to find a process by name, and ps -p PID -f to inspect a known process.

# List all visible processes once
ps aux

# Monitor processes live
top

# Find a process by name
pgrep -a firefox

# Inspect a known PID
ps -p 1234 -f

These commands answer different questions: ps provides a snapshot, top and htop monitor changes, pgrep locates processes, and systemctl provides service-manager context.

What does “running process” mean?

In everyday Linux troubleshooting, “running processes” usually means processes that currently exist, whether they are using the CPU or waiting. In Linux process-state terminology, however, R means running or runnable: a process is executing or ready to be scheduled. Most healthy processes spend much of their time sleeping.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Common state codes include:

Code Meaning
R Running or runnable
S Interruptible sleep
D Uninterruptible sleep, often waiting for I/O
T Stopped or traced
Z Zombie process
I Idle kernel thread, on systems that report it

Every listing is a snapshot or sample. A process can change state or exit immediately after it appears. Visibility also depends on permissions and, inside containers, the current PID namespace.

List processes with ps

Processes attached to your terminal

ps

Plain ps normally shows processes associated with your current effective user and terminal. Typical columns are:

  • PID: process ID.
  • TTY: controlling terminal.
  • TIME: accumulated CPU time.
  • CMD: command or executable name.

That is why plain ps may show only a few entries.

All visible processes

ps aux

ps aux uses BSD-style options and is the familiar Linux command for a full process listing. Do not write it as ps -aux; the ambiguous hyphenated form can be interpreted differently. A full-format alternative is:

ps -ef

Neither command means literally every process everywhere. They show processes visible to the caller in the current host or PID namespace. The ps manual documents selection, formatting, sorting, and state behavior.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Understand ps aux output

Column Meaning
USER User owning the process
PID Process ID
%CPU CPU usage reported by this snapshot
%MEM Percentage of physical memory
VSZ Virtual memory size
RSS Resident memory currently in RAM
TTY Controlling terminal
STAT Process state and additional flags
START Start time or date
TIME Accumulated CPU time
COMMAND Command and arguments

The %CPU value from ps is not a permanent measurement. It can differ from the sampled, continuously updated values shown by top or htop.

Choose columns and sort the result

# Useful custom listing
ps -e -o pid,ppid,user,stat,%cpu,%mem,etime,cmd

# Highest CPU first
ps -e -o pid,ppid,user,stat,%cpu,%mem,etime,cmd --sort=-%cpu

# Highest memory first
ps -e -o pid,ppid,user,stat,%cpu,%mem,etime,cmd --sort=-%mem

The -o option lets you select fields such as the parent PID (PPID), state, elapsed time, CPU, memory, and command line.

List only processes in the R state

ps -e -r -o pid,ppid,user,stat,%cpu,%mem,cmd

On Linux procps, -r restricts selection to processes currently running or runnable. The output may be empty or very short because processes frequently sleep, and state can change during sampling.

For a teaching-oriented display filter, you can inspect the state field explicitly:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
ps -e -o pid,stat,cmd | awk '$2 ~ /^R/'

This is not a perfectly synchronized measurement: ps has already taken its snapshot before awk filters it.

Monitor processes live with top

top

top provides a dynamic system summary and repeatedly samples process information. Inside top:

  • Press q to quit.
  • Press P to sort by CPU usage.
  • Press M to sort by memory usage.
  • Press 1 to show individual CPU states.
  • Press k to enter a PID and send a signal.
  • Press c to toggle command name and full command line where supported.
  • Press H to toggle thread display on implementations that support it.

For a noninteractive sample suitable for remote diagnostics or scripts:

top -b -n 1

Use multiple samples when investigating a transient spike. A single snapshot can miss it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use htop for easier interactive inspection

htop

htop offers scrolling, filtering, tree display, mouse interaction, and convenient process selection. It is not guaranteed to be installed by default, and controls vary by version and configuration. Press F1 or ? inside the program for the applicable help screen.

# Current user's processes
htop -u "$USER"

# Only selected PIDs
htop -p 1234

# Tree view
htop -t

Distribution-specific installation examples are:

# Debian or Ubuntu
sudo apt install htop

# Fedora
sudo dnf install htop

# Arch Linux
sudo pacman -S htop

Package names and package managers differ across Linux distributions. See the htop manual for supported options and process-state details.

Find a process by name with pgrep

# Match the process name and show PID plus name
pgrep -a firefox

# Search the complete command line
pgrep -af 'python.*app.py'

# Limit the search to your user
pgrep -u "$USER" -a

# Find processes in the R state
pgrep -r R -a

pgrep prints matching PIDs directly, making it more suitable for scripts than a pipeline through grep. Without -f, it matches the process name rather than the complete command line. Its patterns are regular expressions, so quote patterns when needed. See the pgrep manual.

Avoid the fragile beginner pattern:

ps aux | grep firefox

It can match the grep command itself and can miss a process when the desired text appears only in its arguments. If a pipeline is unavoidable, grep '[f]irefox' avoids matching that exact grep command, but pgrep is the preferred solution.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

View parent-child relationships

# Show a process tree with PIDs
pstree -p

# Start at a particular PID
pstree -p 1234

# Alternative using ps
ps -e --forest

A tree reveals which shell, wrapper, supervisor, script, or service launched a process and which worker processes it created. This is often more useful than a flat list when diagnosing service restarts or unexpectedly inherited processes. See the pstree manual.

Inspect a specific PID

ps -p 1234 -f

ps -p 1234 -o pid,ppid,user,stat,lstart,etime,%cpu,%mem,cmd

For lower-level kernel-exposed details, inspect the process’s numeric directory under /proc:

cat /proc/1234/status
tr '' ' ' < /proc/1234/cmdline
readlink -f /proc/1234/exe
readlink -f /proc/1234/cwd
ls -l /proc/1234/fd

status contains structured metadata, cmdline contains the argument list, exe points to the executable, cwd identifies the working directory, and fd lists open file descriptors. Access can be restricted by ownership, security policy, mount options, or namespaces. See the proc(5) and proc_pid(5) documentation.

A PID identifies a process instance, not a permanent application identity. The process may exit between commands, and a PID can eventually be reused. Before acting on a PID obtained earlier, verify its command line or executable if the operation matters.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check processes belonging to a systemd service

# Inspect a known service
systemctl status nginx

# List currently running service units
systemctl list-units --type=service --state=running

# Show the service's main PID
systemctl show nginx -p MainPID

Systemd services and Linux processes are related but not identical. A service unit may supervise a main process plus workers, and a process may exist without being managed by systemd. Systemd groups service processes in cgroups, allowing status output to show the unit’s associated process group.

systemctl list-units concerns units currently loaded and, by default, active, failed, or pending units. systemctl list-unit-files --type=service answers a different question: which service unit files are installed.

# Discover installed service names
systemctl list-unit-files --type=service

# Check a user-level service
systemctl --user status service-name

If a service is “not found,” it may have a different unit name, may not be managed by systemd, may belong to a user session, or the distribution may use another init system. The systemctl manual documents the available unit and process views.

Shell jobs are different from system processes

To see background and stopped jobs launched by the current shell, use:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
sleep 300 &
jobs -l

fg %1
bg %1

jobs -l reports the shell’s job-control table, not every process on the system. A job can contain a process group, while ps and top provide broader process views.

List numeric process directories in /proc

printf '%sn' /proc/[0-9]*

Numeric directory names correspond to PIDs visible in the current /proc mount. This demonstrates the underlying interface but is not a replacement for ps: it does not format metadata, shell globbing can be awkward if there are no matches, and processes may disappear while you inspect them. The /proc filesystem may also be restricted with options such as hidepid.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshoot missing or unexpected processes

Only a few processes appear

Use ps aux or ps -ef instead of plain ps. If information about another user’s processes is still missing, permissions, hidepid, SELinux, ptrace restrictions, or container isolation may be responsible. Administrative access may reveal more, but it should not be assumed to bypass every security policy.

A process is missing inside a container

PID namespaces control process visibility. A process list inside a container may show only processes in that namespace, while the host can see additional processes. Therefore, “all processes” always means all processes visible from the current namespace and subject to its permissions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

pgrep finds nothing

The executable name may differ from the name you searched for, the text may appear only in arguments, the process may have exited, or your permissions may limit visibility. Try a full-command-line search:

pgrep -af 'full-or-partial-command-line'

top shows high CPU but ps does not

This can be normal. ps reports a snapshot, while top and htop calculate changing values from samples over time. Capture repeated snapshots:

ps -eo pid,ppid,user,stat,%cpu,%mem,etime,cmd --sort=-%cpu | head
sleep 1
ps -eo pid,ppid,user,stat,%cpu,%mem,etime,cmd --sort=-%cpu | head

The process disappeared or the PID changed

Processes can terminate between discovery and inspection. A PID refers to one process instance and may eventually be reused. Scripts should handle missing PIDs and verify /proc/PID/cmdline or /proc/PID/exe before sending a signal.

The process is a zombie

A Z process has already exited but remains as an entry until its parent collects the exit status. Killing the zombie itself is generally ineffective. Investigate the parent process and its reaping behavior rather than treating the zombie like a live worker.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Threads appear as separate tasks

A process can contain multiple threads. Depending on command options and configuration, ps, top, and htop can display threads as well as processes. Do not automatically interpret every displayed task as a separate application.

Quick command reference

Task Command What it shows
Current terminal processes ps One-time snapshot
All visible processes ps aux BSD-style full listing
All visible processes, full format ps -ef Full-format listing
Live resource view top Continuously updating display
Interactive viewer htop Scrollable and filterable view
Find by name pgrep -a name Matching PIDs and names
Search full command line pgrep -af pattern Arguments included in matching
Process hierarchy pstree -p Parent-child tree with PIDs
Current shell jobs jobs -l Jobs known to this shell
Only R-state processes ps -e -r ... Running or runnable snapshot
Known systemd service systemctl status name Unit state and associated processes
Kernel-level details /proc/PID/* Raw process metadata

Stopping a process: proceed carefully

Listing a process is harmless; sending it a signal can interrupt work or stop a service. If you have confirmed the PID and need to act:

kill PID
kill -TERM PID
kill -KILL PID

SIGTERM is the normal graceful request. SIGKILL prevents cleanup and should be reserved for cases where a process will not respond to safer signals. Recheck the PID immediately before acting, particularly in scripts or automated troubleshooting.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.