How to create a memory dump in Linux
Posted: Wed Mar 25, 2026 10:48 am
This article describes how to configure dump for capturing memory dumps, including application memory.
To create a memory dump of a virtual machine: HOWTO: Get a memory dump of a virtual machine from its hypervisor.
Details
The recommended text editor is nano, below is a quick tutorial on how to use it if you are using it for the first time.
Quick description of nano's basic functions
Configure kdump
Altlinux
There is no kdump-tools package in the default repository, so it has to be downloaded from the sisyphus repository:
Go to https://packages.altlinux.org/en/sisyph ... ump-tools/
In List of rpms provided by this srpm select the kdump-tools package for the required architecture (can be checked by running uname -m)
Download the package from the Download link
Install it by running
apt-get update && apt-get install <path to the downloaded rpm>
After that, follow the Debian instruction from Edit /etc/default/kdump-tools step
Red Hat based distributions (tested on Fedora 38, Rocky Linux 9, Red OS)
Install kexec-tools
sudo dnf install kexec-tools
Edit /etc/kdump.conf. In the configuration file edit the core_collector setting: option -d should be set to 17 instead of 31
Edit /etc/default/grub. Edit GRUB_CMDLINE_LINUX, add crashkernel=256M to reserve enough RAM for the dump kernel to run, and nmi_watchdog=1, to capture a dump in case of a system hang
Run
sudo grub2-mkconfig -o /boot/grub2/grub.cfg
Reboot
Enable kdump service
sudo systemctl enable --now kdump.service
Debian based distributions (tested on Debian, Astra CE, Alt Linux)
Install kdump-tools
sudo apt update && sudo apt install kdump-tools -y
Edit /etc/default/kdump-tools. In the configuration file edit the MAKEDUMP_ARGS variable: option -d should be set to 17 instead of 31
Configure the bootloader
In /etc/default/grub edit GRUB_CMDLINE_LINUX_DEFAULT, add nmi_watchdog=1 to capture a dump in case of a system hang
In /etc/default/grub.d/kdump-tools.cfg change crashkernel value to 384M-:256M (default is 384M-:128M)
Expected result: GRUB_CMDLINE_LINUX_DEFAULT="$GRUB_CMDLINE_LINUX_DEFAULT crashkernel=384M-:256M"
Save and run sudo update-grub
SUSE Linux
Install kdump
sudo zypper in kdump kexec-tools
Edit /etc/sysconfig/kdump
Change KDUMP_DUMPLEVEL variable to 17
Edit /etc/default/grub
Edit GRUB_CMDLINE_LINUX_DEFAULT, add crashkernel=256M to reserve enough RAM for the dump kernel to run, and nmi_watchdog=1, to capture a dump in case of a system hang
Update the bootloader configuration
sudo grub2-mkconfig -o /boot/grub2/grub.cfg
Reboot
Enable kdump service
sudo systemctl enable --now kdump.service
Configure SysRq dump trigger
To enable SysRq trigger, these key combinations 'kernel.sysrq = 8'(without quotes) has to be added to /etc/sysctl.conf.
In SUSE the value of kernel.sysrq has to be changed in /usr/lib/sysctl.d/50-default.conf instead of /etc/sysctl.conf
Reboot or run
sudo sysctl --system
After the set up above is complete, to manually trigger a dump press Alt+SysRq, Alt+C. Alternatively:
echo 8 | sudo tee /proc/sys/kernel/sysrq
(Command above is only needed if kernel.sysrq is not set in /etc/sysctl.conf)
echo c | sudo tee /proc/sysrq-trigger
Location of the dump files may vary between different Linux versions, it is configurable in the kdump configuration file. In Debian based distributions it is set by KDUMP_COREDIR variable. In Red Hat based distributions it is set by the path setting, generally the default location is /var/crash. Make sure that the dump folder has enough free space for the dump to be written. You may search by filemask: vmcore.
To create a memory dump of a virtual machine: HOWTO: Get a memory dump of a virtual machine from its hypervisor.
Details
The recommended text editor is nano, below is a quick tutorial on how to use it if you are using it for the first time.
Quick description of nano's basic functions
Configure kdump
Altlinux
There is no kdump-tools package in the default repository, so it has to be downloaded from the sisyphus repository:
Go to https://packages.altlinux.org/en/sisyph ... ump-tools/
In List of rpms provided by this srpm select the kdump-tools package for the required architecture (can be checked by running uname -m)
Download the package from the Download link
Install it by running
apt-get update && apt-get install <path to the downloaded rpm>
After that, follow the Debian instruction from Edit /etc/default/kdump-tools step
Red Hat based distributions (tested on Fedora 38, Rocky Linux 9, Red OS)
Install kexec-tools
sudo dnf install kexec-tools
Edit /etc/kdump.conf. In the configuration file edit the core_collector setting: option -d should be set to 17 instead of 31
Edit /etc/default/grub. Edit GRUB_CMDLINE_LINUX, add crashkernel=256M to reserve enough RAM for the dump kernel to run, and nmi_watchdog=1, to capture a dump in case of a system hang
Run
sudo grub2-mkconfig -o /boot/grub2/grub.cfg
Reboot
Enable kdump service
sudo systemctl enable --now kdump.service
Debian based distributions (tested on Debian, Astra CE, Alt Linux)
Install kdump-tools
sudo apt update && sudo apt install kdump-tools -y
Edit /etc/default/kdump-tools. In the configuration file edit the MAKEDUMP_ARGS variable: option -d should be set to 17 instead of 31
Configure the bootloader
In /etc/default/grub edit GRUB_CMDLINE_LINUX_DEFAULT, add nmi_watchdog=1 to capture a dump in case of a system hang
In /etc/default/grub.d/kdump-tools.cfg change crashkernel value to 384M-:256M (default is 384M-:128M)
Expected result: GRUB_CMDLINE_LINUX_DEFAULT="$GRUB_CMDLINE_LINUX_DEFAULT crashkernel=384M-:256M"
Save and run sudo update-grub
SUSE Linux
Install kdump
sudo zypper in kdump kexec-tools
Edit /etc/sysconfig/kdump
Change KDUMP_DUMPLEVEL variable to 17
Edit /etc/default/grub
Edit GRUB_CMDLINE_LINUX_DEFAULT, add crashkernel=256M to reserve enough RAM for the dump kernel to run, and nmi_watchdog=1, to capture a dump in case of a system hang
Update the bootloader configuration
sudo grub2-mkconfig -o /boot/grub2/grub.cfg
Reboot
Enable kdump service
sudo systemctl enable --now kdump.service
Configure SysRq dump trigger
To enable SysRq trigger, these key combinations 'kernel.sysrq = 8'(without quotes) has to be added to /etc/sysctl.conf.
In SUSE the value of kernel.sysrq has to be changed in /usr/lib/sysctl.d/50-default.conf instead of /etc/sysctl.conf
Reboot or run
sudo sysctl --system
After the set up above is complete, to manually trigger a dump press Alt+SysRq, Alt+C. Alternatively:
echo 8 | sudo tee /proc/sys/kernel/sysrq
(Command above is only needed if kernel.sysrq is not set in /etc/sysctl.conf)
echo c | sudo tee /proc/sysrq-trigger
Location of the dump files may vary between different Linux versions, it is configurable in the kdump configuration file. In Debian based distributions it is set by KDUMP_COREDIR variable. In Red Hat based distributions it is set by the path setting, generally the default location is /var/crash. Make sure that the dump folder has enough free space for the dump to be written. You may search by filemask: vmcore.