Server Management (Unmanaged)

Managing a Linux Server in Real-time

By the Domain India teamPublished 9 min read
Knowledge base article
Contents (10 sections)

This is a worked example of looking after a Linux server when something goes wrong, and of the routine checks that stop it going wrong again. It follows one administrator through an alert on a server running AlmaLinux, Rocky Linux or Ubuntu, using current commands at each step. It applies to a server you manage yourself, such as a VPS; on shared hosting you can't run these commands or change server settings.

Key takeaways

When a server slows down, work in order: log in with an SSH key, check load and memory (uptime, free -h, top), find the busy process, then check disk (df -h), network (ip a, ss -tulpn) and logs (journalctl). Stop a runaway process with kill (SIGTERM) before kill -9, restart one service rather than the whole server, and confirm the fix. Then automate the routine: updates, backups, a firewall, fail2ban and a scheduled audit.

1. The scenario and the ground rules

Your monitoring reports that a website on your VPS is slow and sometimes times out. Before touching anything, three rules:

  • Look before you change. Read-only commands first; changes only once you know the cause.
  • Change one thing at a time, and note what you changed, so you can undo it.
  • Keep a way back in. Don't restart SSH or change firewall rules without a second session open.

Several older tutorials use ifconfig, netstat and yum. They still exist on some systems, but ip, ss and dnf are the current tools and are what this guide uses. CentOS Linux is end of life; AlmaLinux and Rocky Linux are its drop-in replacements.

2. Log in and take a first look

bash
ssh -i ~/.ssh/id_ed25519 [email protected]
uptime                 # load averages for 1, 5 and 15 minutes
free -h                # memory and swap in use
top                    # live view; press P for CPU order, M for memory, q to quit

Read the load average against the number of CPU cores (nproc). A load of 4 on a 4-core server is busy but coping; a load of 12 means work is queuing. If memory is nearly full and swap is growing, the server is short of RAM, which slows everything down. htop gives a friendlier view if it is installed.

3. Find what is using the resources

bash
ps aux --sort=-%cpu | head -n 10     # top CPU users
ps aux --sort=-%mem | head -n 10     # top memory users
sudo iotop -o                        # processes doing disk I/O (install iotop first)
vmstat 2 5                           # CPU, memory, swap and I/O every 2 seconds

In our scenario, ps shows a PHP-FPM pool and a stuck backup script using most of the CPU. Before stopping anything, find out what it is: ps -fp 1234 shows its full command line, and ls -l /proc/1234/cwd (with the real process ID) shows the directory it runs from.

4. Check disk, network and logs

Disk. A full disk breaks databases, mail and logins.

bash
df -h                                  # space per filesystem
df -i                                  # inodes; a full inode table also stops writes
sudo du -xh --max-depth=1 /var | sort -h | tail

Network.

bash
ip -br a                               # interfaces and addresses
ss -tulpn                              # listening ports and the program behind each
ss -s                                  # connection summary; thousands of connections may mean an attack
ping -c 4 1.1.1.1 && mtr -rwc 20 example.com

Logs.

bash
sudo journalctl -p err -b              # errors since the last boot
sudo journalctl -u nginx --since "1 hour ago"
sudo dmesg -T | grep -iE "error|oom|killed"
sudo tail -f /var/log/nginx/error.log  # use your web server's log path

An Out of memory: Killed process line in dmesg tells you the kernel ran out of RAM and killed something to survive.

5. Fix the problem safely

Stop a runaway process politely first, and forcefully only if it ignores you:

bash
kill <PID>          # sends SIGTERM, letting it clean up
sleep 10
kill -9 <PID>       # SIGKILL, only if it is still running

If the process belongs to a service, restart the service rather than killing it:

bash
sudo systemctl restart php8.3-fpm      # use your service name and version
sudo systemctl status php8.3-fpm
Don't delete log files that are still open

Removing an active log with rm doesn't free the space while a program still has it open. Empty it instead with sudo truncate -s 0 /path/to/file.log, or set up logrotate. For systemd's journal, use sudo journalctl --vacuum-size=500M.

If the backup script was the cause, move it to a quiet hour and give it a lower priority with nice -n 19 ionice -c3 /path/to/backup.sh in its cron line.

6. Confirm the fix

bash
uptime && free -h
ss -tulpn | grep -E ":80|:443"
curl -sI https://example.com | head -n 1
sudo journalctl -p err --since "10 minutes ago"

The load should fall over the next few minutes, the site should answer with a 200, and no new errors should appear. Write down what happened and what you changed.

7. Routine maintenance

Once the fire is out, make the routine automatic.

  1. Apply updates.
    sudo dnf upgrade --refresh on AlmaLinux or Rocky Linux, sudo apt update && sudo apt upgrade on Ubuntu or Debian. Automatic security updates are available with dnf-automatic or unattended-upgrades. Reboot when a new kernel is installed.
  2. Schedule backups.
    Add a cron entry with crontab -e, for example 0 2 * /usr/local/bin/backup.sh, and copy the results off the server. Test a restore now and then.
  3. Keep a firewall.
    On AlmaLinux or Rocky Linux: sudo firewall-cmd --permanent --add-service=https && sudo firewall-cmd --reload. On Ubuntu: sudo ufw allow 443/tcp. Rules added without --permanent disappear at the next reload.
  4. Rotate logs.
    Check that logrotate covers your application logs, not only the system ones.
  5. Watch disk growth.
    A weekly df -h in your monitoring, or an alert at 80 per cent full, prevents most outages.

8. Hardening the server

  • SSH. In /etc/ssh/sshd_config (or a file in /etc/ssh/sshd_config.d/), set PermitRootLogin no and PasswordAuthentication no once your key works, then run sudo sshd -t to test the file before sudo systemctl reload sshd. See the SSH hardening checklist.
  • fail2ban. Blocks IPs that keep failing to log in. On AlmaLinux or Rocky Linux it comes from EPEL: sudo dnf install epel-release fail2ban, then sudo systemctl enable --now fail2ban. On Ubuntu: sudo apt install fail2ban.
  • Database. For MariaDB, run sudo mariadb-secure-installation on a new server, and keep the database listening on 127.0.0.1 unless another server really needs it.
  • Regular audits. Lynis reviews your configuration and suggests fixes: sudo lynis audit system. Schedule it weekly and read the report.
  • Kernel tuning. Change sysctl values only to solve a measured problem. Settings copied from old guides, such as tcp_window_scaling, are already on by default in current kernels.

For firewalls, current guidance favours firewalld, ufw or nftables. The CSF firewall is no longer developed by its original author, so don't choose it for a new server. See modern firewall management with nftables.

9. Running this on a Domain India VPS

Everything above applies to a server you control. A Domain India VPS is self-managed: you get root access and look after the software, updates and security yourself.

  • Rebooting. Reboot from inside the server with sudo reboot. Don't use poweroff or shutdown -h: a VPS you switch off from inside stays off until support starts it again.
  • When the VPS stops responding, or you need it started, force-restarted, reinstalled or resized, open a ticket with the VPS's IP address and support will do it. See managing your VPS.
  • On shared hosting (cPanel, DirectAdmin or Webuzo) you can't install packages, change the firewall or restart services. Use your control panel's tools, and ask support for anything at server level.
VPS Starter
₹552.65/mo + GST
  • 1 vCPU
  • 2 GB DDR4 RAM
  • 64 GB NVMe SSD Storage
  • 2 TB Monthly Bandwidth
See plan details
VPS Basic
₹1,105.30/mo + GST
  • 2 vCPU
  • 4 GB DDR4 RAM
  • 128 GB NVMe SSD Storage
  • 3 TB Monthly Bandwidth
See plan details

Prices on the cards are live Domain India list prices and exclude 18% GST.

Frequently asked questions

What should I check first when a Linux server is slow?

Check the load average with uptime, memory with free -h, and the busiest processes with top or ps aux sorted by CPU and memory. Then check disk space with df -h and recent errors with journalctl -p err.

Should I use kill -9 to stop a process?

Only as a last resort. Plain kill sends SIGTERM, which lets the program close files and clean up. Use kill -9 only if the process is still running after that. If it belongs to a service, restart the service with systemctl instead.

Are ifconfig and netstat still used?

They are deprecated on most current distributions. Use ip a for interfaces and addresses, and ss -tulpn for listening ports and connections.

How do I free disk space safely?

Find what is large with du and df, empty active log files with truncate rather than deleting them, set up logrotate, and shrink the systemd journal with journalctl --vacuum-size.

Is CentOS still a good choice for a server?

No. CentOS Linux has reached end of life and gets no security updates. Use AlmaLinux, Rocky Linux, Ubuntu LTS or Debian for new servers.

How do I restart a Domain India VPS that isn't responding?

Open a support ticket with the VPS's IP address and support will start or force-restart it. If you can still log in, reboot from inside with sudo reboot.

Can I run these commands on shared hosting?

No. Shared hosting doesn't give you root access, so you can't install packages, change the firewall or restart services. Use your control panel, or a VPS if you need that control.

Ready to run your own server? Compare VPS plans, read the essential Linux commands guide, or open a support ticket if your VPS needs a restart from our side.

A server you control

Root access on a KVM VPS, with the Linux distribution of your choice.

See VPS plans

Ready when you are

Get VPS from ₹552.65/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app