How to check Mac CPU usage and find the app behind it

The fan is loud, the case is warm, and the obvious move is to open Activity Monitor and look at the CPU tab. What appears is a list of thirty processes with percentages that change every five seconds, a name like kernel_task somewhere near the top, and no indication of which number is the one to act on.

Checking CPU usage is easy. Checking it in a way that names the responsible app, and that separates a four second spike from a background job running all afternoon, takes a few more steps. Three of them are in the View and Window menus rather than on the tab itself, and one of them is in Terminal.

What the CPU tab is actually measuring

Open Activity Monitor from Applications, then Utilities, and click CPU. The list of processes is the same list shown on every other tab. What changes is the columns, and on the CPU tab the one that matters is % CPU.

Sorting it is the whole technique. Clicking a column heading sorts the list, and clicking the same heading again reverses the order, so one click on % CPU puts the busiest process at the top. Reading the list unsorted is how people end up worrying about whichever system process happens to be near the top alphabetically.

The three figures along the bottom of the window are more useful than most of the columns, because they say where the work is going rather than how much there is. Apple defines them exactly.

System: The percentage of CPU capability that's being used by processes that belong to macOS. User: The percentage of CPU capability that's being used by apps you opened, or by the processes opened by those apps. Idle: The percentage of CPU capability that's not being used. Source: support.apple.com, read September 27, 2026

That split does real work. A machine sitting at high User is busy with something that was asked for, and the process list will name it. A machine sitting at high System with nothing obviously running is a different situation, usually indexing, syncing, or a background service retrying something that keeps failing. The two call for different responses, and the percentages at the bottom are the fastest way to tell them apart.

The CPU tab is a snapshot, not a history. It reports what is happening in the current sampling window and keeps no record of the last hour. A process at 90 percent for three seconds while a page renders is normal. The same process at 20 percent continuously for an hour is the real finding, and the CPU tab cannot distinguish them on its own.

Three views of CPU, and when each one is right

Activity Monitor has three CPU displays, and only one of them is the tab.

The Window menu holds the other two. CPU Usage opens a small floating meter that shows current activity, which is the right tool for a question like whether a specific action spikes the processor. It stays visible while other apps are in front, so the action and the reading can be watched together.

CPU History, also under Window, is the one that answers intermittent problems. It draws a scrolling graph per core, so a fan that spins up every few minutes appears as a regular pattern of spikes rather than as a number that was high when nobody was looking. A recurring job and one busy afternoon look identical on the CPU tab and completely different here.

The third display is the Dock icon. Apple's instruction is to choose View, then Dock Icon, then "select the Show CPU option you want to view". That turns the Activity Monitor icon itself into a live readout, which is the lowest effort way to keep an eye on the processor over a working day without a window in the way.

There is a trade in using the Dock icon or the floating meter: both require Activity Monitor to stay running, and Activity Monitor itself uses processor time to update. That cost is measurable rather than theoretical, and the next section covers how to see it.

Narrowing the list until the answer is in it

The default list is every process the current user can see, which is more than is useful. The View menu turns it into a short list.

Apple documents twelve grouping options, and four of them do most of the work. My Processes "shows processes owned by your user account", which removes the system noise. System Processes "shows processes owned by macOS", which is the right filter when the System percentage at the bottom of the window is the high one. Active Processes "shows running processes that aren't sleeping". Applications in last 12 hours shows "only the apps running processes in the last 12 hours", which is the closest thing to a history in the process list itself.

All Processes, Hierarchically is the one to reach for before quitting anything. It "shows processes that belong to other processes, so you can see the parent/child relationship between them", which is how a helper that looks idle on its own turns out to be the only thing holding a running app together.

Two smaller controls finish the job. The search field at the top right filters by name, which is faster than scrolling when the suspect is already known. View, then Columns adds columns that are hidden by default, including CPU Time, and double-clicking a process opens a window of detail about it.

CPU Time deserves a mention of its own, because it answers a question % CPU cannot. It accumulates since the process started, so a process with a large CPU Time and a low % CPU has been busy earlier and is quiet now. That is exactly the shape of a background job that already did its damage.

The update frequency changes what the numbers mean

Activity Monitor refreshes on a timer, and the timer is adjustable. Apple states the default: "By default, the information is updated every 5 seconds, but you can update information more frequently for more precise monitoring." The control is under View, then Update Frequency.

Both directions are useful. A faster refresh catches short spikes that a five second window averages away, which matters when trying to link a specific click to a specific process. A slower refresh makes trends readable, because the list stops reordering itself every few seconds and the eye can follow a single row.

Apple attaches a warning and a way to check it. The warning is that "increasing the update frequency may affect your overall system performance". The check is to "watch the CPU Time column in the CPU pane of the Activity Monitor window as you change the update frequency", which shows how much processor time the monitoring itself is consuming. That is an unusually honest piece of documentation, and it settles the question of whether leaving Activity Monitor open at a fast refresh is free. It is not.

For diagnosing a warm Mac, the practical setting is the slowest refresh with the CPU History window open. The graph carries the pattern, the list stays still enough to read, and the measurement costs close to nothing.

top in Terminal, for the numbers Activity Monitor leaves out

The command line version gives one figure Activity Monitor does not show at all, and it makes repeatable measurement much easier.

The figure is the load average. The top manual defines it as the "load average over 1, 5, and 15 minutes", where the load average is "the average number of jobs in the run queue". Three numbers falling from left to right mean a burst that is ending. Three numbers rising mean something is still arriving. No single percentage in Activity Monitor carries that shape.

A handful of options cover almost every use. top sorts by process ID by default, which is rarely what is wanted, so -o cpu sorts by CPU usage instead. The manual also documents -u as "an alias equivalent to: -o cpu -O time", which sorts by CPU usage and breaks ties by execution time. -n limits the display to a set number of processes, -s sets the delay between updates in seconds with a default of one second, and -stats limits the output to a named list of columns.

Two options make it scriptable. -l switches to logging mode and prints a given number of samples as plain text rather than redrawing the screen, which is how a reading gets captured into a file for comparison later. The manual attaches an important caveat to it: "the first sample displayed will have an invalid %CPU displayed for each process, as it is calculated using the delta between samples". Anyone taking a single sample and trusting the percentages is reading noise.

-pid and -user narrow the output to one process or one account, which is the command line equivalent of the View menu groupings. The global line at the top reports CPU "broken into user, system, and idle components", matching the three figures at the bottom of the CPU tab.

A busy processor is not a battery verdict

The most common misuse of the CPU tab is answering a battery question with it. The CPU tab has no memory, so it cannot say what drained the battery over the morning. The Energy tab can.

Question Where to look The reading that answers it
What is busy right now CPU tab, % CPU sorted descending the top few rows
Is the work macOS or an app CPU tab, figures at the bottom System against User
Has this been happening repeatedly Window, then CPU History the pattern of spikes per core
What has cost battery today Energy tab, 12 hr Power column the top rows of that column
Is something keeping the Mac awake Energy tab, Preventing Sleep column a Yes in that column
How loaded is the machine overall top in Terminal the 1, 5 and 15 minute load averages

Apple defines the Energy columns clearly. Energy Impact is "a relative measure of the current energy consumption of the app (lower is better)". 12 hr Power is "the average energy impact of the app in the last 12 hours, or since the Mac computer started", and the guide notes that this column "only appears on Mac laptops". Preventing Sleep shows "whether this app is preventing your Mac from going to sleep", which is the answer to a laptop that was warm and flat after being closed.

The Energy tab is also where resident background apps stop being invisible. Utilities that sit at the top of the screen and run all day appear in 12 hr Power even though they were never opened, and that list is usually shorter and more surprising than the list of apps in the Dock. Deciding which of them to remove is a separate exercise from deciding which of them need an icon on screen, and the features page covers the second half.

Stopping the process without losing work

Once a process is named, the stop button at the top left of the window offers two options, and they are not interchangeable.

Quit, in Apple's words, "is the same as choosing File > Quit within an app. The process quits when it's safe to do so. If quitting the process could cause data loss or interfere with another app, the process doesn't quit." Force Quit is blunter: "the process quits immediately. If the process has files open, you may lose data. If the process is used by other apps or processes, those apps or processes could experience problems."

Quit first, every time. A refusal to quit is information rather than a failure, and the hierarchical view explains most refusals. Unresponsive processes are marked "(Not Responding)" and shown in red, which is the one case where reaching for Force Quit early is reasonable. Processes belonging to another user may ask for administrator authentication, which is a good moment to stop and reconsider rather than to type a password.

For processes that need a specific signal rather than a termination, View, then Send Signal to Process offers a pop-up menu of signals. That is a developer tool more than a troubleshooting one, and it is worth knowing it exists before following instructions that mention it.

What to change first

Sort % CPU descending, read the System and User figures at the bottom, then open CPU History from the Window menu before concluding anything, because a snapshot cannot tell a spike from a pattern. If the process that keeps appearing is a utility that runs all day at the top of the screen, the next question is which of those still need to be there, and Koffret is for deciding what stays visible in that row.

Frequently asked questions

Why does kernel_task show high CPU usage?

kernel_task belongs to macOS rather than to any app, so a high figure next to it is a symptom rather than a cause. Sort the % CPU column and read the rows around it, and check the System percentage at the bottom of the window, which shows how much of the processor macOS itself is using.

What is a normal CPU usage percentage on a Mac?

There is no single number, because the CPU tab reports a moment rather than an average. Apple's own framing is the useful one: Idle is the percentage not being used, so a machine with high Idle between bursts is healthy regardless of how high the bursts go. Sustained low Idle with no app in front is the condition worth investigating.

How can CPU usage be checked from Terminal?

The top command lists processes with their CPU usage. Sorting by processor time needs an option, because top sorts by process ID by default, and the manual documents -o cpu for that. The load average on the top line, covering 1, 5 and 15 minutes, is a figure Activity Monitor does not display at all.

Does leaving Activity Monitor open slow the Mac down?

It has a cost, and Apple documents how to measure it. Increasing the update frequency "may affect your overall system performance", and watching the CPU Time column while changing the frequency shows how much processor time the monitoring is using. The slowest update frequency keeps that cost negligible.

Which tab shows what is draining the battery?

The Energy tab, sorted by 12 hr Power, which averages each app's energy impact over the last twelve hours or since startup and appears only on laptops. The Preventing Sleep column on the same tab covers the separate case of a Mac that loses charge with the lid closed.

Back to all posts