pstree
Overview
pstree shows running processes as a tree, making parent/child relationships obvious — ideal for seeing what a supervisor spawned, which shell owns a pipeline, or how threads hang under a process.
Syntax
pstree [options] [pid|user]Common Options
| Option | Description |
|---|---|
-a |
Show command-line args |
-p |
Show PIDs |
-c |
Don’t compact identical subtrees |
-h / -H pid |
Highlight current / specified |
-n |
Sort by PID |
-u |
Show uid transitions |
-g |
Show PGID |
-s |
Show parents of specified PID |
-l |
Long lines (no truncation) |
-T |
Hide threads |
-A / -U |
ASCII / UTF-8 lines |
-Z |
SELinux context |
-t |
Show full thread names when available |
Examples with Explanations
Basics
pstree
pstree -p
pstree -apOne user or PID
pstree alice
pstree -p 1
pstree -ap $(pidof -s nginx)Show ancestry of a process
pstree -s -p 12345
ps -o pid,ppid,cmd -p 12345Avoid compaction
pstree -c -pIdentical child names are otherwise merged with counts.
Threads vs processes
pstree -p 12345
pstree -T -p 12345SELinux
pstree -ZCompare with ps
ps auxf
pstree -ap
systemd-cglsps f / ps --forest is another forest view; systemd-cgls shows cgroup trees.
Notes / Pitfalls
- Large trees on busy hosts are noisy — filter by user/PID.
- Compact mode can hide multiplicity — use
-cwhen counting workers. - Permission: some args may be invisible for other users’ processes.
- PID namespaces in containers show a nested world (PID 1 is container init).
- Not a real-time monitor — re-run or use
watch -n1 pstree -p.
2026-relevant notes
- systemd-heavy systems: also learn
systemctl statusandsystemd-cgtop. - For containers:
podman top/docker top+ hostpstree -pwith care. - Kernel threads appear under
kthreadd(PID 2) on the host.
Additional Resources
man pstree