When your own Linux server slows down or a service stops, a short, fixed routine finds the cause faster than guessing: check load, memory, disk and failed services, then read the logs of whatever broke. This guide gives that routine with current commands for AlmaLinux, Rocky Linux and Ubuntu, plus notes for servers running a control panel such as cPanel/WHM, DirectAdmin or CyberPanel.
This guide is for a server you manage, such as a VPS with root access; on shared hosting you can't run these commands, and the server is ours to fix. Work in order: uptime and top for load, free -h and the kernel log for memory and OOM kills, df -h and df -i for disk, systemctl --failed for broken services, then journalctl and the service's own log. Change one thing at a time and keep a note of what you changed.
Shared hosting customers can't change server settings or restart services. For a slow or broken site on shared hosting, start with My website is slow and check your hosting resource usage, or open a ticket.
1. Load and CPU
nproc # number of CPU cores
uptime # load averages for 1, 5 and 15 minutes
top -c # live view; press P to sort by CPU, M by memory
ps aux --sort=-%cpu | head -15
ps -eo user,%cpu,%mem,cmd --sort=-%cpu | head -15 # which userRead the load average against the core count. A load of 4 on a 4-core server means the CPUs are fully busy; well above that means work is queueing. On Linux, load also counts processes waiting for disk, so a high load with low CPU use in top usually points to slow storage (section 3), not to the processor.
htop is friendlier than top; install it with dnf install htop (from EPEL on AlmaLinux and Rocky) or apt install htop.
2. Memory and out-of-memory kills
free -h # look at the "available" column, not "free"
vmstat 1 5 # si/so above 0 means the server is swapping
journalctl -k | grep -iE "out of memory|oom-kill|killed process"Linux uses spare RAM as disk cache, so low "free" memory is normal. Trouble is low "available" memory, steady swapping, or OOM kills in the kernel log. When the OOM killer strikes, it usually picks the biggest process: MySQL, PHP-FPM or a Node.js app.
The usual fixes:
- Size PHP-FPM to your RAM. Set
pm.max_childrento roughly the memory you can give PHP divided by the size of one PHP process (check it withps -o rss= -C php-fpm). Too high a value is what exhausts memory under load. - Size MySQL's buffer pool to leave room for the web server and PHP. See MySQL performance optimisation.
- Add a small swap file as a safety net on small servers, not as a substitute for RAM.
- Move to a bigger plan when real usage has outgrown the server.
3. Disk space and disk I/O
df -h # space per filesystem
df -i # inodes: "no space left" can mean no inodes left
du -xh --max-depth=1 / 2>/dev/null | sort -h | tail -15
journalctl --disk-usageA full / or /var breaks databases, mail and logins. Common culprits are old backups, log files that never rotate, the systemd journal and forgotten dumps in /root or /home. Cap the journal with journalctl --vacuum-size=500M, and check that logrotate covers your application logs.
For slow storage, install sysstat and look at utilisation and wait times:
iostat -x 2 5 # %util near 100 and high await = saturated disk
iotop -o # which processes are doing the I/O (needs root)
systemctl enable --now sysstat && sar -u # history, once collection has run4. Failed services and logs
systemctl --failed
systemctl status nginx # or httpd, apache2, mariadb, mysqld, php-fpm
journalctl -u nginx -b --no-pager | tail -50
journalctl -p err -b # every error since the last bootAlways test a web server's configuration before you restart it, so a typo doesn't take every site down:
| Service | Test the configuration | Main error log |
|---|---|---|
| Nginx | nginx -t | /var/log/nginx/error.log |
| Apache (AlmaLinux, Rocky) | httpd -t | /var/log/httpd/error_log |
| Apache (Ubuntu) | apache2ctl configtest | /var/log/apache2/error.log |
| PHP-FPM | php-fpm -t (the binary name varies by version) | journalctl -u php-fpm, or the pool's log |
| MySQL or MariaDB | mysqld --validate-config (MySQL 8) | journalctl -u mariadb or mysqld |
The error Can't connect to local MySQL server through socket means the database isn't running or the socket path is wrong. Check systemctl status mariadb (or mysqld), read its log, and check free disk space before restarting it.
5. Network and DNS
ss -tulpn # which services listen on which ports
curl -sI https://example.com
dig +short example.com A # does the domain point at this server's IP?
dig +short NS example.com # which nameservers answer for itIf a site doesn't load, confirm that the domain points to your server, the service is listening, and the firewall allows the port. /etc/resolv.conf only controls which DNS resolver the server itself uses; it has nothing to do with where your domain points. For a site that won't resolve, see How to change your domain's DNS settings.
6. Security and firewall
- SSH: log in with keys, set
PasswordAuthentication no, and usePermitRootLogin prohibit-passwordor a sudo user. Follow the SSH security hardening checklist. - Firewall: use
firewalldon AlmaLinux and Rocky, orufwon Ubuntu, and open only the ports you use. See modern firewall management with nftables. - Brute-force protection:
fail2banworks on both families. Don't run two tools that both manage the firewall. - CSF: its original developer stopped maintaining it in 2025. Existing installs keep working (
csf -g IPfinds a block,csf -dr IPremoves a deny,csf -a IPallows an IP), but on a new server prefer firewalld or ufw. See diagnosing CSF IP blocks. - Updates: apply security updates regularly with
dnf upgradeorapt upgrade, and reboot when the kernel changes.
Take a snapshot or backup first, change one setting at a time, and keep a second SSH session open when you edit SSH or firewall rules, so a mistake doesn't lock you out.
7. Servers running a control panel
A panel manages its own services, so use its tools rather than editing files it will overwrite.
| Panel | Restart a service | Useful logs |
|---|---|---|
| cPanel/WHM | /scripts/restartsrv_httpd (also _mysql, _nginx, _cpanel_php_fpm) | /usr/local/cpanel/logs/error_log |
| DirectAdmin | systemctl restart httpd (or nginx); rebuild with CustomBuild in /usr/local/directadmin/custombuild | /var/log/directadmin/ |
| CyberPanel | systemctl restart lsws (OpenLiteSpeed) | /usr/local/lsws/logs/error.log |
On panel servers, change PHP versions, PHP-FPM pools and web server mode from the panel (WHM MultiPHP Manager, DirectAdmin CustomBuild, the CyberPanel interface), so your changes survive panel updates.
8. Running this on Domain India
Everything above applies to a VPS or server you manage. Our VPS is self-managed by default, with full root access and a choice of Linux distributions including Ubuntu, Debian, AlmaLinux and Rocky Linux. The VPS page lists free CyberPanel and optional DirectAdmin at ₹600 a month. We don't offer cPanel on VPS; for cPanel, use our shared cPanel hosting.
- 1 vCPU
- 2 GB DDR4 RAM
- 64 GB NVMe SSD Storage
- 2 TB Monthly Bandwidth
- 2 vCPU
- 4 GB DDR4 RAM
- 128 GB NVMe SSD Storage
- 3 TB Monthly Bandwidth
Prices on the cards are live and exclude 18% GST. Compare every plan on VPS servers, or read VPS vs shared hosting if you are not sure you need a server of your own.
Does this guide apply to Domain India shared hosting?
No. It is for a Linux server you manage yourself, such as a VPS with root access. On shared hosting you can't restart services or change server settings; check your resource usage in the control panel and contact support for anything server-side.
What is a high load average?
Compare it with the number of CPU cores, which nproc shows. A load equal to the core count means the CPUs are fully used; well above it means work is waiting. High load with low CPU use usually means processes are waiting for the disk.
How do I know if my server ran out of memory?
Search the kernel log with journalctl -k for "out of memory" or "killed process". Also check the available column of free -h and the si and so columns of vmstat, which show swapping.
My disk shows free space but I get "No space left on device". Why?
The filesystem may be out of inodes, which happens with millions of small files such as cache or session files. Check with df -i and delete the unneeded files.
Can I get cPanel on a Domain India VPS?
No. The VPS page lists free CyberPanel and optional DirectAdmin. For cPanel, use our shared cPanel hosting plans.
Should I still install CSF on a new server?
Its original developer stopped maintaining it in 2025. Existing installs keep working, but on a new server firewalld (AlmaLinux, Rocky) or ufw (Ubuntu) with fail2ban is the safer long-term choice.
Ready to take control of your own server? Compare VPS plans, harden it with the SSH security checklist, or open a ticket if you are unsure whether a VPS is right for you.
KVM VPS with full root access, NVMe storage and your choice of Linux distribution.
See VPS plans