A technician runs `vmstat 2` on a sluggish application server and observes the following steady-state output: procs -----------memory---------- ---swap-- -----io---- ---system-- ------cpu----- r b swpd free buff cache si so bi bo in cs us sy id wa st 2 3 512000 20480 10240 102400 850 920 1200 1400 3000 4500 10 5 20 65 0 What does the si and so column data most strongly indicate?
- ANetwork throughput is saturated, causing the observed slowness
- BThe system has abundant free memory and swap is idle as expected
- CThe system is actively swapping memory pages in and out of disk, indicating memory pressure and likely performance degradation
- DThe CPU is the bottleneck due to high user time (us) values
Show answer & explanationAnswer & explanation
Correct answer: C. The system is actively swapping memory pages in and out of disk, indicating memory pressure and likely performance degradation
The si (swap-in) and so (swap-out) columns show KB/s of memory being paged to and from swap space. Sustained non-zero values of 850 and 920 indicate the system is actively swapping due to insufficient physical RAM, which combined with wa=65 (65% CPU time waiting on I/O) strongly points to memory pressure causing disk-bound thrashing and poor responsiveness.
Why the other options are wrong
- A. vmstat does not report network statistics at all; this column set is unrelated to network throughput.
- B. si/so of 0 would indicate idle swap; these are clearly non-zero and significant.
- D. us is only 10%, so CPU user time is not the bottleneck here.
vmstat Swap Columns (si/so)
si (swap-in) and so (swap-out) in vmstat report the rate, in KB/s, that memory pages move between RAM and swap space; sustained high values indicate memory pressure and thrashing.
- si = swap-in (KB/s), so = swap-out (KB/s)
- High wa (I/O wait) combined with high si/so confirms swap thrashing
- Fix: add RAM, reduce memory usage, or tune swappiness (vm.swappiness)
Memory trick: Elephant-sized memory demand forces pages to swap in and out — si/so are the footprints.