Linux free Command: Check Memory and Swap Usage
free is a command that provides a summary of the usage of physical memory (RAM) and swap on a Linux system. When determining whether memory is insufficient, it is better to first check the available column, which estimates the amount that can be used to start new programs without swapping, rather than the free column at face value.
free -h
Linux uses unused RAM for things like file caching and reclaims it when needed. Therefore, you should not conclude that memory is low just because the free value is small and buff/cache is large.
Information shown by the free command
free reads /proc/meminfo provided by the kernel to calculate information about physical memory and swap. The definitions of each column and options can be found in the official procps-ng free manual.
free -h
A typical output looks similar to the following. The values are examples, and the display format may vary depending on the system and procps-ng version.
total used free shared buff/cache available Mem: 15Gi 4.2Gi 1.1Gi 320Mi 9.7Gi 10Gi Swap: 2.0Gi 128Mi 1.9Gi
Understanding the meaning of each column
total, used, free
| Column | Meaning | Interpretation |
|---|---|---|
total |
Total Usable Physical Memory | It may not be exactly the same as the total installed RAM. Areas reserved by the kernel and hardware are excluded. |
used |
Memory that is in use or not immediately available | Currently, procps-ng calculates it as total - available physical memory. The calculation method may have differed depending on the version. |
free |
Memory that is not used for any purpose | Does not include memory used as cache that can be reclaimed. |
shared and buff/cache
shared mainly represents memory used in tmpfs. buff/cache is the sum of kernel buffers, page cache, and reclaimable slab memory.
Cache stores data read from the disk in RAM to allow faster re-access. If an application needs memory, the kernel can reclaim it, so having a large cache is not problematic by itself.
Why available is important
available is an estimated value of memory that can be used to start new applications without using swap. It does not simply add free + buff/cache, but uses the kernel's MemAvailable information, which takes into account page cache and some of the reclaimable slab.
This value is also not an absolute guarantee of future memory usage. If an application suddenly requests a large amount of memory or if the kernel has trouble reclaiming memory, the situation can change quickly.
Difference between Mem and Swap rows
Physical memory row
The Mem row summarizes the total size and usage of actual RAM. It includes various uses such as application memory, kernel, cache, and shared memory.
Swap row
Swap shows the total, used, and free capacity of the swap area, not RAM. You cannot conclude that there is currently a memory shortage just because swap usage is not 0. This is because inactive pages that were previously pushed out may remain in swap even after there is available RAM.
Conversely, if swap usage continues to increase, and si and so in vmstat occur continuously, and response time worsens, memory pressure should be suspected.
vmstat 1
Frequently used options
Display in human-readable units
free -h
-h or --human automatically selects binary units like Ki, Mi, Gi depending on the value. If a fixed unit is needed, you can use -m, -g, etc.
free -m free -g
View buffers and cache separately
free --wide
-w or --wide separates buff/cache into the buffers and cache columns. To analyze the detailed cause, you should also look at /proc/meminfo, slabtop, and others.
Repeated display at regular intervals
free -h -s 2
-s 2 continuously displays the results at 2-second intervals. To print only a set number of times, use -c together.
free -h -s 2 -c 5
View total physical memory and swap
free -h --total
-t or --total adds a column total. Since RAM and swap have different performance and roles, do not interpret the total alone as the actual available high-speed memory.
How to determine memory shortage
View available memory together with swap I/O
It is better to observe the following signals rather than just a single free output.
- Whether
availablecontinues to be lower than usual - Whether swap usage is increasing
- Whether
siandsoinvmstatoccur continuously - Whether service response time and disk I/O deteriorate together
- Whether there are OOM (Out of Memory) termination records in the kernel log
free -h vmstat 1 journalctl -k -g 'oom\|Out of memory\|Killed process'
Searching with journalctl may yield no results depending on the distribution and log settings, and permission to read the log may be required.
Finding processes that use a lot of memory
In ps, you can sort by memory usage to check the top processes.
ps -eo pid,user,%mem,rss,comm --sort=-rss | head
RSS indicates the amount of pages currently loaded in physical memory, but shared pages may be counted multiple times across processes. To analyze containers, shared libraries, and file mappings precisely, consider cgroup metrics and tools like smem together.
Do not unconditionally clear the cache
Page cache is managed by the kernel to improve system performance. Forcing the cache to be cleared to make the numbers in free smaller can increase disk reads and actually reduce performance. Only perform this when there is a clear purpose, such as a reproducible performance test, and when you understand the impact and recovery methods.
Points to consider for units and automation
Binary units and decimal units
The default -h display uses the KiB, MiB, GiB series based on 1024. Using --si uses the kB, MB, GB series based on 1000.
free -h --si
Mixing different units in documentation or monitoring can create discrepancies, so specify the standard.
Do not parse the display string as-is
The columns and calculation methods of free can vary by procps-ng version, and human-readable units are not suitable for parsing. In automation, if possible, use the required entries from /proc/meminfo or structured metrics provided by monitoring agents, and fix the units and version.
Why free values appear large in containers
free reads /proc/meminfo. Depending on the container runtime and cgroup configuration, this file may show values close to the total host memory, which can differ from the actual memory limits applied to the container.
When determining a container's available capacity, be sure to check the orchestrator's requests and limits, the cgroup memory limits and current usage, and OOM events together. It is important not to conclude the memory available to a container based solely on the host's free value.
Frequently Asked Questions
Does almost 0 free mean the memory is insufficient?
Not necessarily. When Linux uses leftover memory as cache, free may be small. Check available, swap I/O, and service performance together.
Is all buff/cache memory reclaimable?
Some can be reclaimed when needed, but not all can be immediately reclaimed. available is an estimate that considers this difference, so it's better not to simply add all of buff/cache as free memory.
Does using swap always mean RAM is insufficient?
No. Inactive pages from the past may remain in the swap. You need to check the trend of increasing swap usage, along with actual swap input/output and delays.
Why does the used value appear different from other tools?
The way cache and reclaimable memory are classified may vary depending on the tool and version. Compare the /proc/meminfo at the same point in time, the procps-ng version, and each tool's definitions.
Summary
free -h is a basic command to quickly check the status of RAM and swap. To determine memory shortage, you should look not at just the free column but consider available, swap input/output, process usage, and service delays together.
If the load is high at the same time, refer to how to interpret the average load using the uptime command to also check for CPU and I/O bottlenecks.









