Ask Steves · Daily notes · VPS, 20% off · AI Profit Lab · SEO · Money Hub

6 September 2026 · One command a day

How do I see which process is using a port on Linux?

The command ss -ltnp lists every TCP port your server is listening on, along with the process that owns each one. You reach for it when a service refuses to start because its port is already in use, or when you want to know exactly what is exposed to the internet before you touch the firewall. It is installed by default on Ubuntu 24.04 and takes under a second to run.

The command

sudo ss -ltnp

ss stands for socket statistics and is the modern replacement for netstat. The -l flag shows only listening sockets, which is what a server does while it waits for connections. -t limits the list to TCP. -n prints numeric ports such as 443 instead of names such as https, which is easier to search. -p adds the name and process ID of whatever owns the socket. You need sudo for that last part, because a normal user can only see process details for their own processes.

What you will see

State   Recv-Q  Send-Q  Local Address:Port   Peer Address:Port  Process
LISTEN  0       511           0.0.0.0:80          0.0.0.0:*      users:(("nginx",pid=1234,fd=6),("nginx",pid=1233,fd=6))
LISTEN  0       511           0.0.0.0:443         0.0.0.0:*      users:(("nginx",pid=1234,fd=7),("nginx",pid=1233,fd=7))
LISTEN  0       4096        127.0.0.1:3000        0.0.0.0:*      users:(("node",pid=2345,fd=19))
LISTEN  0       4096        127.0.0.1:5432        0.0.0.0:*      users:(("postgres",pid=987,fd=7))
LISTEN  0       128           0.0.0.0:22          0.0.0.0:*      users:(("sshd",pid=890,fd=3))
LISTEN  0       128              [::]:22             [::]:*      users:(("sshd",pid=890,fd=4))

The column to read first is Local Address:Port. An address of 0.0.0.0 means the service accepts connections on every IPv4 interface, so it is reachable from outside if the firewall allows it. 127.0.0.1 means only programs on the same machine can reach it, which is what you want for a database or a Node app sitting behind nginx. [::] is the IPv6 equivalent of 0.0.0.0. The Process column gives the program name and its PID, which you can pass straight to kill or systemctl. Ports published by Docker show up under a process called docker-proxy rather than the container name.

When to use it

Watch out for

Running it without sudo is the classic mistake. The port list still appears, but the Process column is blank for anything owned by another user, including nginx, sshd and most Docker containers. It is easy to look at that empty column and conclude nothing is using the port, then spend an hour chasing the wrong problem. Also remember that -t hides UDP. If you are looking for DNS, WireGuard or anything else on UDP, run sudo ss -lunp instead.

Questions people ask

What is the difference between ss and netstat?

netstat is the older tool and is not installed on a fresh Ubuntu 24.04 server. ss does the same job, reads directly from the kernel, and takes the same flags, so netstat -ltnp becomes ss -ltnp.

How do I check just one port?

Add a filter at the end, for example sudo ss -ltnp 'sport = :3000'. Piping to grep :3000 works too and is easier to remember.

Shared hosting never lets you see this, because the ports belong to someone else. On a server you control, every socket is yours to inspect, move or close. You can get the same VPS with 20% off at https://asksteves.co.uk/vps. Affiliate link.

Everything on this blog runs on one Hostinger KVM 8. This link takes 20% off the same box.

GET A VPS, 20% OFF →

Affiliate link.

More daily notes: Index