Linux uptime Command: Check Uptime and Load Averages
uptime is a command that shows the current time, the time the system has been running since the last boot, the number of logged-in users, and the average load for the last 1, 5, and 15 minutes, all in a single line. It is used as a starting point to quickly check when the server was rebooted or to determine whether the load is temporary or persistent.
uptime
However, average load is not the same as CPU usage. It represents the average number of tasks that are either runnable or waiting for I/O in an uninterruptible state, so for accurate interpretation, you need to consider the number of CPUs as well as the status of disk and network.
How to read uptime output items
The typical output format is as follows. Actual times and numbers vary by system.
14:32:10 up 12 days, 3:41, 2 users, load average: 0.42, 0.51, 0.48
The procps-ng uptime official manual explains that this single line consists of the current time, uptime, number of logged-in users, and the 1-, 5-, and 15-minute average load.
| Output example | Meaning | Points to be careful about when interpreting |
|---|---|---|
14:32:10 |
Current time of the system | Affected by timezone and time synchronization settings. |
up 12 days, 3:41 |
Elapsed time since last boot | In containers, the host uptime may be displayed. |
2 users |
Number of login sessions | Counts based on login records, not unique individuals. |
0.42, 0.51, 0.48 |
1-minute, 5-minute, 15-minute average load | Not a percentage normalized by the number of logical CPUs. |
Interpreting Each Item in Detail
Current Time
The first value is the current time recognized by the system. If it does not match the log time, check the timezone and synchronization status with timedatectl.
timedatectl status
System Uptime
After up, the elapsed time since the last boot is displayed. If it is shorter than expected, check the system logs and boot records for unplanned reboots, kernel errors, power issues, or administrative tasks.
uptime -p uptime -s
-p shows the elapsed time in a readable format, and -s shows the time the system started. Supported options may vary depending on the version of procps-ng installed on your distribution, so check with uptime --help.
Number of Logged-in Users
The number of users is calculated based on currently logged-in sessions. If the same user logs in multiple times via SSH and console, it may be counted as multiple sessions. To see who is logged in, use w or who.
w who
What is load average?
Time ranges of the three numbers
The three values of the average load represent the load over the last 1 minute, 5 minutes, and 15 minutes, respectively. It is not a simple arithmetic average but an exponentially weighted moving average that gives more weight to recent states, so it does not directly show the number of tasks at a specific moment.
- If the 1-minute value is higher than the 5-minute and 15-minute values, it may indicate that the recent load is increasing.
- If the 1-minute value is lower, it may indicate that the previously high load is easing.
- If all three values are similarly high, it may indicate that the load is sustained.
Compare with the number of CPUs
The average load is not normalized by the number of CPUs. First, check the number of logical CPUs and then compare it with the load.
nproc
For example, in a system with 4 logical CPUs, a load of 1.00 has a different meaning than 1.00 on a system with a single CPU. As a simple rule of thumb, if the load is similar to the number of logical CPUs, it may indicate that the executable tasks are using a significant portion of the CPU capacity, but this alone cannot confirm a bottleneck.
Why it differs from CPU usage
The average load in Linux includes not only tasks running or waiting to run on the CPU, but also tasks waiting on I/O in an uninterruptible state. Therefore, even if CPU usage is low, average load can rise due to slow disks or network storage.
If the load is high, you need to check CPU usage, run queue, I/O wait, memory, and swap together.
top vmstat 1 iostat -xz 1 free -h
iostat is usually included in the sysstat package and might not be installed.
Frequently used uptime options
Readable uptime display
uptime --pretty
-p or --pretty outputs only the uptime in a human-readable sentence. It is not suitable for parsing in scripts where the sentence may be affected by language.
Check Boot Time
uptime --since
-s or --since displays the system start time in the format YYYY-MM-DD HH:MM:SS. Since this value is calculated based on the current time, verify it along with the boot logs on systems where the time setting has been significantly changed.
Container and Raw Format Options
The latest procps-ng has the --container option to request the container uptime and the --raw option to display the current time and uptime in seconds.
uptime --container uptime --raw
These options may not be available in older distributions of procps-ng. If the container runtime or the kernel does not provide the related information, the expected values may not appear, so you should check support in the actual environment.
Order of Checks When Average Load is High
Start by checking trends and the number of CPUs
- Check whether the 1-minute, 5-minute, and 15-minute values from
uptimeare increasing, decreasing, or steady. nprocis used to check the number of logical CPUs.- Use
toporpsto find processes that are using a lot of CPU. - Use
vmstatandiostatto check the run queue and I/O wait. - Use
freeto check available memory and swap usage.
Do not conclude a failure based on a single number.
It can be normal for the 1-minute load to spike briefly due to short compression tasks or backups. On the other hand, if the 15-minute value continues to rise and response times deteriorate, it is likely a persistent bottleneck. Thresholds should be set not only based on CPU count, but also considering usual traffic, task types, storage performance, and service latency.
If regular observation is necessary, it is better to collect average load, CPU, I/O, memory, and application metrics together from a monitoring system rather than relying on one-time uptime output.
Points to watch for in containers and virtual machines
The uptime of a virtual machine usually indicates the running time of the guest operating system. Since containers share the host kernel, depending on the tool and environment, the host's uptime may be displayed. Check the support for --container in the latest procps-ng, the namespace configuration of the container runtime, and the data source of the monitoring system together.
Also, the CPU limits assigned to a container and the values reported by nproc may not always match the capacity expected by the administrator. It is safe to also check the CPU requests and limits of the container orchestrator and throttling metrics.
Frequently Asked Questions
Does a load average of 1.00 mean 100% CPU usage?
No. The average load reflects the number of tasks in runnable or uninterruptible I/O wait states and is not normalized by the number of CPUs. CPU usage should be separately checked using tools like top or mpstat.
Why did the uptime suddenly shorten?
In most cases, the system has been rebooted. Check whether it was a planned update, or if there were power issues or kernel errors using journalctl --list-boots, system logs, and operational records. Depending on the log retention settings, previous boot records may not exist.
Why is the number of logged-in users different from the actual number of people?
If a single person opens multiple SSH or console sessions, each can be counted separately, and there may be cases where login records appear abnormal. Check the terminal and login time using w or who.
How can I continuously check uptime?
You can run it at regular intervals using watch.
watch -n 5 uptime
If you need long-term trends and alerts, use a monitoring system instead of watching the output screen.
Summary
uptime is the first step to quickly check whether the system has rebooted and the load trend. The three average loads in the output represent 1-minute, 5-minute, and 15-minute intervals, not CPU usage or percentages.
When the average load is high, check the number of logical CPUs, CPU usage, run queue, I/O wait, and available memory and swap together. How to interpret memory items can be found in Using the free command.









