The “lsof” command in Linux stands for “List Open Files”. At any given time in Linux, thousands or even tens of thousands of files are open. Unlike in a system like Windows, Linux famously treats everything as a file, so this command allows you to examine every aspect of a system, regardless of whether it’s a network connection, devices, or even directories. Knowing how to use the lsof command for debugging can save you hours as you try and figure out which process is using a particular resource that you’re trying to release. In this article, let’s see the various use cases of lsof and some of the command parameters.
Using lsof to Examine Open Files
The most basic way to use lsof is to just use it as a standalone command:
sudo lsof
If you have root privileges, you should use “sudo” to get access to all open files, instead of simply “lsof”, since most of the files will be hidden from regular users by default. The problem with this is that it’s not very useful. It’ll list all the open files on your system, which will zoom past without any context, and can take a long time to list as well. Here’s a screenshot:

As you can see, this by itself is a terrible debugging tool. What we need is a way to filter down the files that are of interest to us. And so lsof has several options that we use. Here’s the syntax:
lsof [options] [file] [user] [process] [host] [port]
No one uses lsof without including at least one of these options – often more. The ability to filter down and see the exact files that are of interest is the key skill while using lsof.
Specifying Ports, Hostnames, Usernames, and Process IDs
The first question to ask is whether you want to filter by:
- File name
- Users
- Processes
- Hosts
- Ports
Searching by Filename
To search for a file, simply type:
lsof [filename]
Like this:

Not all filenames are actual files in the traditional sense, of course. Many files, like the one above – /dev/kmsg are device files. For example, earlier I’d written about using dev/shm to share data between applications. But they’re technically files, and searchable via lsof.
Searching for Network Files
These are some of the most common filetypes you’ll be searching for with lsof. We use it to search for network sockets, representing network connections based on all kinds of parameters. To see all network files, we type:
sudo lsof -i
This gives us:

Of course, this is a test system, and there are very few actual connections. On an actual server, you’ll have a lot more network files, so we need a way to filter even these. We can filter them using the following criteria:
- Hostnames (@google.com) lsof -i @192.168.1.1
- Port numbers (:443) lsof -i :443
- Protocol (TCP) lsof -i TCP
We can also combine the various filters in the following ways:
- lsof -i TCP:22 (TCP protocol, port 22)
- lsof -i @google.com:443 (Hostname is Google, connected on port 443)
- lsof -i [email protected]:53 (TCP protocol, on hostname at a specific port)
Combinations of these three types of filters should be enough to let you isolate whatever you want for debugging purposes.
Other options are commonly used as well, but are simple to explain. Here are some:
- Usernames (-u)
- Commands (-c)
In the following section, let’s explore some of the most common use cases for lsof and see what makes it so valuable in debugging.
Use Cases for lsof
Lsof is such a flexible tool that there are dozens of use cases for debugging. Here are some popular examples:
All Processes Using Network Sockets
You can quickly use lsof to list all the network resources in use on the server. The command for that is:
lsof -i -n -P
We’ve already seen that “-i” is the flag for network, but -n and -P add a special twist. “-n” skips the hostname resolution that can add lag to the command, and in many cases, isn’t necessary. “-P” shows port numbers instead of service names, which are often useful when debugging. This command is fast and can quickly give you an overview of network consumption on your server. Here’s a sample output:

As you can see, there are no hostnames, and so the command executes instantaneously.
List Open Processes by ID
Often, when you need to shut down a process, you might want to see which files it’s using. You can do a quick check with lsof to see which files a process is keeping open, using this command:
lsof -p 1234
You can even use multiple processes by separating them with a comma:
lsof -p 1234,5678,9012
Replace the numbers above with the process IDs.
See Which Process is Using Which Files
We’ve seen before that you can mount ISO files in Linux. Here’s a tutorial on using the mount command in general. But when trying to unmount a directory, you often get an error message or warning saying that some files and directories of the mount are still in use. To see which files are being used in a certain directory, use the following command:
lsof +D /mnt/data/
The “/mnt/data” is the directory in question, and the “+D” command instructs lsof to progress down the directory recursively and check all the files that might be open in that directory. Once you deal with all the processes and open files, you won’t get the “device busy” errors anymore. This command will also give you the owner of the process and the type of file.
List Files Opened by a Specific User
In addition to listing files by process, you can also see files a particular user has open using the command:
lsof -u john
As we’ve noted earlier, “-u” is the flag instructing lsof to filter by user.
Listing Just the PIDs
While lsof is useful as a visual aid to show the administrator which files are being used, you can also use it in scripts, and therefore, we need a way to reduce its output. We can instruct lsof to return just the process IDs of those processes that are using a particular resource, so we can take mass action on them all at once.
For example, let’s say you’re trying to run a service on a specific port, but your system informs you that the port is already in use. You can get a list of all processes using a particular port using this command:
lsof -t -i :3000
This command uses the “-t” command, which instructs lsof to output only the PIDs instead of all the other file details. We can then feed this list into a kill command like this:
kill -9 $(lsof -t -i :3000)
This command will kill all processes linked to the port number 3000. Needless to say, this is something you should use carefully and only when you know what you’re doing!
Conclusion
As you can see, the lsof command is incredibly versatile. You can use it for debugging a wide range of situations, and even use it in scripting to perform mass actions to free up a certain resource. As a Linux administrator, you’ll find yourself using it over and over, and it’s well worth the effort to familiarize yourself with it.

I’m a NameHero team member, and an expert on WordPress and web hosting. I’ve been in this industry since 2008. I’ve also developed apps on Android and have written extensive tutorials on managing Linux servers. You can contact me on my website WP-Tweaks.com!

Leave a Reply