Lsof Command Practice
lsof answers the question "what process owns this port, file, or socket?" by querying the kernel's open-file table. This track drills the filter flags you reach for when debugging a port conflict, tracking a runaway process, or tracing which service holds a log file open.
Command Reference
basic
| Command | Description |
|---|---|
lsof | List every open file on the system — all processes, all file descriptors. |
sudo lsof -u root | List all files opened by the root user, requiring elevated privileges to see all root-owned processes. |
lsof -t -i :<port> | Print only the PIDs of processes with a file open on the given port — no column headers, one PID per line. |
lsof -n -i | List all network connections without resolving hostnames to IP addresses, speeding up output on slow DNS. |
lsof -P -i | Display port numbers as integers instead of service names like 'ssh' or 'http'. |
port
| Command | Description |
|---|---|
lsof -i :<port> | Show which processes have a socket open on a specific port number. |
lsof -i UDP | Show all processes with any open UDP socket. |
lsof -i :<port1> -i :<port2> | Show processes using either of two specified port numbers (OR logic when the same flag is repeated). |
lsof -i TCP:<port> | List processes with a TCP socket open on a specific port, excluding UDP connections on the same port. |
lsof -i TCP:<start>-<end> | List all processes with a TCP socket in the given port range — useful for scanning privileged ports or ephemeral ranges. |
lsof -i @<host> | List all network connections to or from a specific remote IP address or hostname. |
lsof -i TCP -s TCP:ESTABLISHED | Show only TCP connections that are currently in the ESTABLISHED state, filtering out listeners and TIME_WAIT. |
process
| Command | Description |
|---|---|
lsof -c <name> | List all files opened by any process whose name starts with the given string. |
lsof -p <pid> | Show all files opened by the process with the given PID. |
lsof -c <name1> -c <name2> | List files opened by processes matching either of two name prefixes (OR across repeated -c flags). |
lsof -p ^<pid> | Show files opened by all processes except the one with the specified PID. |
lsof -t -p <pid> | Print only the PID of the matched process — useful for confirming PID existence or feeding into another command. |
lsof -i -c <name> | Show network connections belonging to a named process, combining network filter with process name filter. |
user
| Command | Description |
|---|---|
lsof -u <user> | List all files opened by a specific user across all their processes. |
lsof -u <user1> -u <user2> | List files opened by either of two users — repeated -u flags are OR'd together. |
lsof -u ^<user> | Show files opened by every user except the specified one — caret negates the user filter. |
lsof -i -u ^root | Show all network connections excluding those owned by root, scoping output to application-level processes. |
lsof -t -u <user> | Print only PIDs of all processes belonging to a user — useful for bulk kill by user. |
network
| Command | Description |
|---|---|
lsof -i 4 | List all open network connections using IPv4 only. |
lsof -i 6 | List all open network connections using IPv6 only. |
lsof -i | Show all open network files (sockets), covering both IPv4 and IPv6 across all protocols. |
lsof -i TCP -s TCP:LISTEN | Show only TCP sockets that are actively listening for incoming connections. |
file
| Command | Description |
|---|---|
lsof <file> | Show which processes have a specific file path open. |
lsof /var/log/<logfile> | Find which daemon or process currently has a log file open — useful when you cannot delete or rotate a log. |
lsof +D <dir> | Recursively list all files open within a directory and its subdirectories. |
lsof | grep deleted | Find processes holding open file descriptors to files deleted from disk — the space is not freed until those processes close their descriptor. |
combined
| Command | Description |
|---|---|
lsof -n -P -i | List all network connections showing raw IP addresses and numeric port numbers — no hostname or service-name resolution. |
kill -9 $(lsof -t -i :<port>) | Kill the process holding a specific port open by substituting the terse PID output directly into kill. |
kill -9 $(lsof -t -u <user>) | Kill all processes belonging to a user by feeding lsof's terse PID list into kill. |
lsof -a -u <user> -i | Combine user and network filters with AND logic — -a makes all preceding filters intersect rather than union. |
lsof -a -c <name> -i :<port> | Show network connections on a port that belong specifically to a named process, using -a for AND intersection. |
Key Use Cases
- Find which process is listening on port 8080 before starting a new service
- List every file a specific user has open to audit activity
- Kill a process that is holding a port open using lsof -t piped to kill
- Show only TCP or UDP connections for a running daemon
- List all files inside a directory that are currently held open
- Exclude root from a network query to scope to application processes
Frequently Asked Questions
What does the -t flag do in lsof?
-t (terse) prints only the process IDs of matching processes, one per line. This makes it easy to pipe directly into kill: kill -9 $(lsof -t -i :8080).
What is the difference between lsof -i :80 and lsof -i TCP:80?
lsof -i :80 matches any protocol (TCP or UDP) on port 80. lsof -i TCP:80 restricts the match to TCP only. Use the protocol prefix when you need to distinguish between a TCP listener and a UDP service on the same port number.
How do I exclude a user from lsof output?
Prefix the username with ^ to negate it: lsof -u ^root shows all processes except those owned by root. The caret works for -p (PID) as well: lsof -p ^1 excludes PID 1.
Why does lsof +D need a leading + instead of -?
+D (uppercase D, plus prefix) recursively lists all files open beneath a directory. The + prefix is lsof's convention for options that take a value and imply recursive/additive behavior, unlike - flags which typically filter or restrict.
Ready to master Lsof commands?
Test your muscle memory with our spaced-repetition quiz system. Free forever.
