What it is¶
ss (from iproute2) dumps socket information straight from the kernel and replaces netstat, which is deprecated and no longer installed by default on most distributions. It is faster on busy hosts and can filter by state, port, and address.
Which services are listening?¶
sudo ss -tulpn
| Flag | Meaning |
|---|---|
-t / -u |
TCP / UDP |
-l |
listening sockets only |
-p |
owning process (needs root to see other users' processes) |
-n |
numeric ports and addresses, no name lookups |
-a |
all sockets, listening and connected |
-4 / -6 |
one address family |
sudo ss -antlp (TCP only, all states, listening) is a typical variant. Example output:
State Recv-Q Send-Q Local Address:Port Peer Address:Port Process
LISTEN 0 511 0.0.0.0:80 0.0.0.0:* users:(("nginx",pid=2019,fd=6))
LISTEN 0 80 127.0.0.1:3306 0.0.0.0:* users:(("mysqld",pid=1484,fd=21))
127.0.0.1 means local only; 0.0.0.0 or [::] means every interface. Check this when a service is "running" but unreachable from other hosts.
Who is using port 80?¶
sudo ss -ltnp 'sport = :80'
Filtering connections¶
ss -tn state established '( dport = :443 or sport = :443 )'
ss -tn dst 203.0.113.0/24
ss -s # summary counts by state
ss -tni # per-connection TCP internals (rtt, cwnd, retrans)
A TIME-WAIT pile-up and a large Recv-Q on a listener mean different things: Recv-Q on a LISTEN socket is the accept backlog. If it is at the limit, the application is not accepting connections fast enough.
Migrating from netstat¶
| netstat | ss |
|---|---|
netstat -tulpn |
ss -tulpn |
netstat --tcp --listening --program |
ss -tlp |
netstat -lntp \| grep 80 |
ss -lntp 'sport = :80' |
netstat -s |
ss -s (summary) or nstat (protocol counters) |
netstat -i |
ip -s link |
netstat -rn |
ip route |
netstat -an |
ss -an |