Using lsof to Find Open Files and Processes
Linux treats many resources as files, including regular documents, sockets, devices, pipes, and active network connections. The lsof command exposes these relationships, helping administrators identify which process has a file open or which service is listening on a port.
This is useful during routine maintenance on RHEL, CentOS, and Fedora systems. It can reveal why a filesystem will not unmount, which process is consuming a log file, or whether an unexpected daemon has opened a network socket.
Australian administrators may use these checks on servers supporting offices in Sydney, Melbourne, Brisbane, or Perth. Accurate timestamps matter across Australian time zones, while systems connected through NBN links, public Wi-Fi, or cloud regions should be examined with the same care as machines in a local data centre.
Installing And Running lsof
lsof is commonly available from the standard package repositories. On RHEL, CentOS, or Fedora, install it with:
sudo dnf install lsof
Older CentOS releases may use yum instead:
sudo yum install lsof
Running lsof without arguments can produce a large amount of output because it lists open files for many processes. Ordinary users may see only their own processes, so use sudo when investigating system services, protected directories, or another user’s activity.
The output usually includes the command name, process ID, owner, file descriptor, type, device, size, node, and file or network address. A line containing cwd identifies a process’s current working directory, while rtd indicates its root directory.
Finding A Specific Open File
To discover which process is using a file, provide its path:
sudo lsof /var/log/messages
This is especially helpful before rotating, replacing, or deleting a log. If a file has been removed but remains open, the process may continue consuming disk space. Search for deleted files with:
sudo lsof +L1
The +L1 filter shows files with fewer than one link, which normally means they have been unlinked. Restarting the owning service often releases the space, although production systems should be checked carefully before any restart.
You can inspect everything below a directory with:
sudo lsof +D /var/www
For large directory trees, +D can be slow. The +d option checks only the specified directory, making it a better choice when a quick, limited scan is sufficient.
Filtering By Process And User
A process ID is often the fastest route from a symptom to its cause:
sudo lsof -p 2486
To list files opened by a particular command, use -c:
sudo lsof -c nginx
The command name filter can match several processes with the same name. To investigate files owned by a user, use:
sudo lsof -u deploy
You can exclude a user with -u ^deploy, which is useful when narrowing a busy host to system-owned processes. For broader Linux administration guidance, the Linux tutorials on command-line and server maintenance provide useful supporting material.
Inspecting Ports And Network Connections
Network sockets are among lsof’s most practical features. To identify the process listening on TCP port 443, run:
sudo lsof -iTCP:443 -sTCP:LISTEN
For all listening sockets:
sudo lsof -nP -iTCP -sTCP:LISTEN
The -n option prevents DNS lookups, and -P keeps numeric port values instead of converting them into service names. These options usually make output faster and easier to interpret.
Useful network filters include:
-i :22for any connection using port 22-i UDPfor UDP sockets-i @192.0.2.10for a specific remote or local address-ato combine multiple filters with AND logic
When reviewing a service exposed to the internet, compare the process list with firewall rules. A practical firewalld rules guide can help confirm that only intended ports are reachable.
Reading Output During Incident Checks
A typical line may show ESTABLISHED, LISTEN, or CLOSE_WAIT. LISTEN means a process is waiting for new connections, while ESTABLISHED indicates an active session. CLOSE_WAIT can point to an application that has not properly closed a connection.
Use -t when you need only process IDs:
sudo lsof -t -i :8080
This output can be passed to another command, but avoid using automated termination until the process has been identified. A web application, reverse proxy, or backup job may have a legitimate connection.
For Australian organisations, logs and connection details can contain personal information governed by privacy obligations under the Privacy Act 1988. Avoid copying full command output into public tickets, and mask usernames, addresses, and customer-related paths. When auditing traffic associated with online entertainment platforms, background reading on Australian low-volatility pokies may help explain why a monitored application has regular external connections, but it does not replace host-level verification.
Practical Checks For Administrators
A short investigation sequence can answer most open-file questions:
- Identify the affected path, port, or mount point
- Run
lsofwithsudoand stable options such as-nP - Record the process ID, owner, and service name
- Confirm the process before restarting or stopping it
For a server that will not unmount, check the mount directly:
sudo lsof +f -- /mnt/archive
For a suspected deleted log, combine the deleted-file search with process details:
sudo lsof -nP +L1
Use the result alongside ps, systemctl status, journalctl, and firewall inspection. lsof shows what is open at that moment; it does not by itself explain why the process opened it or whether the behaviour is malicious.
On a test RHEL or Fedora virtual machine, create a temporary listener, inspect it with sudo lsof -nP -iTCP -sTCP:LISTEN, then stop the service and verify that the socket disappears. This gives you a safe, repeatable exercise: run that command now and record the process ID attached to port 22.