The first commands to run on a slow or full server
Out of space: df -h shows which filesystem is full, then du on that filesystem finds the directory. Old logs, Docker images and package caches are the usual culprits. If df shows space free but writes still fail, check inodes with df -i: millions of tiny files (sessions, mail queues) can exhaust them.
Slow or overloaded: uptime shows the load average, free -h shows memory and swap, and sorting processes by CPU or memory shows what is responsible. Unexpected outbound connections or a process you do not recognise using all the CPU often mean the server has been compromised.