CmdKeys LogoCommand Quiz

Lsof Command Practice

lsof answers the question "what process owns this port, file, or socket?" by querying the kernel's open-file table. This track drills the filter flags you reach for when debugging a port conflict, tracking a runaway process, or tracing which service holds a log file open.

Command Reference

basic

CommandDescription
lsofList every open file on the system — all processes, all file descriptors.
sudo lsof -u rootList all files opened by the root user, requiring elevated privileges to see all root-owned processes.
lsof -t -i :<port>Print only the PIDs of processes with a file open on the given port — no column headers, one PID per line.
lsof -n -iList all network connections without resolving hostnames to IP addresses, speeding up output on slow DNS.
lsof -P -iDisplay port numbers as integers instead of service names like 'ssh' or 'http'.

port

CommandDescription
lsof -i :<port>Show which processes have a socket open on a specific port number.
lsof -i UDPShow all processes with any open UDP socket.
lsof -i :<port1> -i :<port2>Show processes using either of two specified port numbers (OR logic when the same flag is repeated).
lsof -i TCP:<port>List processes with a TCP socket open on a specific port, excluding UDP connections on the same port.
lsof -i TCP:<start>-<end>List all processes with a TCP socket in the given port range — useful for scanning privileged ports or ephemeral ranges.
lsof -i @<host>List all network connections to or from a specific remote IP address or hostname.
lsof -i TCP -s TCP:ESTABLISHEDShow only TCP connections that are currently in the ESTABLISHED state, filtering out listeners and TIME_WAIT.

process

CommandDescription
lsof -c <name>List all files opened by any process whose name starts with the given string.
lsof -p <pid>Show all files opened by the process with the given PID.
lsof -c <name1> -c <name2>List files opened by processes matching either of two name prefixes (OR across repeated -c flags).
lsof -p ^<pid>Show files opened by all processes except the one with the specified PID.
lsof -t -p <pid>Print only the PID of the matched process — useful for confirming PID existence or feeding into another command.
lsof -i -c <name>Show network connections belonging to a named process, combining network filter with process name filter.

user

CommandDescription
lsof -u <user>List all files opened by a specific user across all their processes.
lsof -u <user1> -u <user2>List files opened by either of two users — repeated -u flags are OR'd together.
lsof -u ^<user>Show files opened by every user except the specified one — caret negates the user filter.
lsof -i -u ^rootShow all network connections excluding those owned by root, scoping output to application-level processes.
lsof -t -u <user>Print only PIDs of all processes belonging to a user — useful for bulk kill by user.

network

CommandDescription
lsof -i 4List all open network connections using IPv4 only.
lsof -i 6List all open network connections using IPv6 only.
lsof -iShow all open network files (sockets), covering both IPv4 and IPv6 across all protocols.
lsof -i TCP -s TCP:LISTENShow only TCP sockets that are actively listening for incoming connections.

file

CommandDescription
lsof <file>Show which processes have a specific file path open.
lsof /var/log/<logfile>Find which daemon or process currently has a log file open — useful when you cannot delete or rotate a log.
lsof +D <dir>Recursively list all files open within a directory and its subdirectories.
lsof | grep deletedFind processes holding open file descriptors to files deleted from disk — the space is not freed until those processes close their descriptor.

combined

CommandDescription
lsof -n -P -iList all network connections showing raw IP addresses and numeric port numbers — no hostname or service-name resolution.
kill -9 $(lsof -t -i :<port>)Kill the process holding a specific port open by substituting the terse PID output directly into kill.
kill -9 $(lsof -t -u <user>)Kill all processes belonging to a user by feeding lsof's terse PID list into kill.
lsof -a -u <user> -iCombine user and network filters with AND logic — -a makes all preceding filters intersect rather than union.
lsof -a -c <name> -i :<port>Show network connections on a port that belong specifically to a named process, using -a for AND intersection.

Key Use Cases

  • Find which process is listening on port 8080 before starting a new service
  • List every file a specific user has open to audit activity
  • Kill a process that is holding a port open using lsof -t piped to kill
  • Show only TCP or UDP connections for a running daemon
  • List all files inside a directory that are currently held open
  • Exclude root from a network query to scope to application processes

Frequently Asked Questions

What does the -t flag do in lsof?

-t (terse) prints only the process IDs of matching processes, one per line. This makes it easy to pipe directly into kill: kill -9 $(lsof -t -i :8080).

What is the difference between lsof -i :80 and lsof -i TCP:80?

lsof -i :80 matches any protocol (TCP or UDP) on port 80. lsof -i TCP:80 restricts the match to TCP only. Use the protocol prefix when you need to distinguish between a TCP listener and a UDP service on the same port number.

How do I exclude a user from lsof output?

Prefix the username with ^ to negate it: lsof -u ^root shows all processes except those owned by root. The caret works for -p (PID) as well: lsof -p ^1 excludes PID 1.

Why does lsof +D need a leading + instead of -?

+D (uppercase D, plus prefix) recursively lists all files open beneath a directory. The + prefix is lsof's convention for options that take a value and imply recursive/additive behavior, unlike - flags which typically filter or restrict.

Ready to master Lsof commands?

Test your muscle memory with our spaced-repetition quiz system. Free forever.

Start Practice Now →