For a running Linux container, the direct command is docker exec <container> ss -tan state established. It lists the container’s established TCP sockets, provided the image includes ss. The important detail is that the command runs in the container’s network namespace, not merely on the Docker host.
Run the established-connection check
Replace web with the container name or ID:
docker exec web ss -tan state established
docker exec starts a command in an already running container. The command must be an executable that exists in the image, and it works only while the container’s primary process is running.
| Part | Meaning |
|---|---|
docker exec web |
Run a process in the network and process view of the running web container. |
ss |
Linux socket-inspection utility. |
-t |
Restrict the listing to TCP sockets. |
-a |
Include listening and non-listening sockets before the state filter is applied. |
-n |
Show numeric addresses and ports instead of resolving names. |
state established |
Keep only sockets whose TCP state is ESTAB or ESTABLISHED. |
The result is a point-in-time snapshot. A connection can close immediately after the command reads the socket table, so an empty result does not prove that an application never connected.
Check prerequisites first
- Docker must be able to address the target container on the machine where you run the command.
- The container must be running. A stopped container has no live socket table for
docker execto inspect. - The image must contain an executable named
ss, or you must use another inspection path. - You need enough permission to execute a process in the container. Additional permission may be needed when requesting process ownership details.
Find the exact name or ID with docker ps. If several containers use similar names, use the full ID or select the intended instance explicitly.
#1 Best Overall
Understand the output
A typical numeric listing has columns similar to these:
State Recv-Q Send-Q Local Address:Port Peer Address:Port
ESTAB 0 0 172.18.0.4:8080 172.18.0.7:53124
- State is the current TCP state.
- Recv-Q and Send-Q are queued bytes waiting to be read or transmitted.
- Local Address:Port identifies the container-side endpoint.
- Peer Address:Port identifies the remote endpoint as seen from that network namespace.
Because -n disables name resolution, numeric output is faster to interpret and avoids confusing reverse-DNS names with the actual peer address. IPv4 and IPv6 sockets can both appear.
Show the owning process when needed
Add -p:
docker exec web ss -tanp state established
This asks ss to include process information. Whether a PID or process name is visible depends on the container’s permissions, process view, and security configuration; do not assume every row will have attribution.
You can also narrow the query. For example, this asks for established TCP sockets involving port 443:
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →docker exec web ss -tan state established '( dport = :443 or sport = :443 )'
Use the local port when you want to verify a server socket, and the destination port when you want to identify outbound traffic. Keep the filter expression quoted so the shell does not interpret its parentheses.
Use the equivalent command with Docker Compose
For a Compose service, run:
docker compose exec web ss -tan state established
Here web is the service name, not necessarily a container name. If the service is scaled to multiple replicas, list the running containers and target the particular replica whose connections you need; otherwise you may inspect a different instance from the one handling the request.
What to do when ss is not installed
Small production images commonly omit diagnostic programs. docker exec does not install a missing executable, so choose an approach that fits your change-control and security policy.
Use a utility already present
Some images provide netstat instead. First check without changing the container:
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Rank #3
docker exec web command -v netstat
docker exec web netstat -tn
Look for rows whose state column is ESTABLISHED. Output columns and filtering syntax vary between implementations, so treat this as an image-specific fallback rather than a portable replacement for ss.
Attach an approved diagnostic container
An organization-approved diagnostic image can be placed in the target container’s network namespace and run a socket utility there. Confirm the image provenance, allowed capabilities, data-handling rules, and cleanup procedure before attaching it. The key requirement is the namespace: a tool in a different namespace will list the wrong sockets.
Inspect the namespace from the Linux host
On a Linux Docker host, you can use the target process’s network-namespace handle. The host must provide the required utilities and permit access to the process namespace.
- Get the container’s init-process PID:
PID=$(docker inspect --format '{{.State.Pid}}' web)
printf '%sn' "$PID"
Verify that the PID is nonzero and that /proc/$PID/ns/net exists before continuing.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
- Create a temporary namespace name and map it to the process’s network namespace:
sudo mkdir -p /var/run/netns
sudo ln -s "/proc/$PID/ns/net" /var/run/netns/container-net
- Run the host’s socket utility in that namespace:
sudo ip netns exec container-net ss -tan state established
- Remove the temporary mapping when finished:
sudo rm /var/run/netns/container-net
This is a Linux-host technique. Distribution packaging, container runtime behavior, permissions, and the availability of ip or ss differ, so validate it in your environment. If the container is replaced, the old PID and namespace handle are no longer the right target.
Why host-wide commands and network inspection can mislead
Running ss directly on the Docker host may show host sockets and connections from many containers. Published ports and NAT rules also describe how traffic is exposed, not the complete live socket list inside one container.
docker network inspect is useful for network configuration and topology—such as attached endpoints and addressing—but it is not a live established-TCP report. Use a socket utility in the target namespace for connection state.
| Method | Best use | Main limitation |
|---|---|---|
docker exec … ss |
Fast, precise inspection when the image includes ss. |
Requires a running container and an installed executable. |
| Approved diagnostic container | Minimal images where policy permits temporary tooling. | Requires the correct namespace, image approval, and permissions. |
| Host namespace method | Linux hosts where the container cannot be modified. | Needs host-level access and compatible namespace utilities. |
docker network inspect |
Network configuration and membership. | Does not list live established sockets. |
Or skip the browser setup
If you also need a clean image of a web dashboard, status page, or incident report for documentation, ScreenshotNeo can return a screenshot or PDF through one request. Its cleanup step accepts cookie-consent banners and removes more than 60 known consent platforms, newsletter popups, and chat widgets before capture. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and the response identifies the page verdict and billing result in headers. Its MCP server lets Claude, Cursor, and other MCP clients call screenshot tools directly.
Free tools Windows power users keep installed
One-click scans. No signup required.
See the parameter reference in the ScreenshotNeo documentation. A one-call example is:
Best Value
- Docker, Docker Swarm, Docker Compose, Programmer, Developer, Coding, Programming, Software Engineer, Code, DevOps, Deploy, Deployment, Kubernetes, Salt, Puppet, Chef, Terraform, Container, AWS, Azure, Cloud, Geek, Funny, Computer, Software, Tech, IT
- Integration, Scrum, Compile, Compilation, Science, Bug, Debug, Python, Linux, Java, Javascript, Scala, Dotnet, Kotlin
- Lightweight, Classic fit, Double-needle sleeve and bottom hem
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://freedom251.com -o shot.webp
The same request from Python:
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://freedom251.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
And from Node.js:
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://freedom251.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
The Free plan includes 1,000 screenshots per month with no card. Paid plans start at $5 for 3,000 screenshots, and every feature is included on every plan. Create a free ScreenshotNeo account.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Troubleshoot common failures
| Symptom | Likely cause | Fix |
|---|---|---|
container ... is not running |
The target’s primary process has stopped. | Check docker ps -a, restart or start the intended container if appropriate, then rerun the command. |
exec: "ss": executable file not found |
The image does not contain ss. |
Use an available utility, an approved diagnostic container in the same namespace, or the Linux host-side method. |
Permission denied for -p |
Process attribution is restricted by permissions or the container’s process view. | Run the basic socket query, or obtain the minimum approved privilege needed for attribution. |
| No rows are returned | No TCP socket was established at that instant, the traffic is UDP, or the command ran in the wrong namespace. | Repeat during the request, confirm the application uses TCP, and verify the container or namespace target. |
| Only host traffic appears | ss was run on the host rather than in the container namespace. |
Use docker exec or the namespace method against the specific container PID. |
| Compose output belongs to the wrong replica | The service has multiple running instances. | Enumerate the instances and execute against the intended container ID. |
| The namespace command fails after a redeploy | The PID or namespace symlink refers to a replaced container. | Remove the old mapping, obtain the new PID, create a new mapping, and rerun. |
Operational notes for repeat checks
- Sample deliberately:
ssis a snapshot, not a history database. For intermittent connections, repeat the command during the suspected event or use an approved monitoring system. - Keep output reproducible: retain
-nand record the container ID, timestamp, and host. Container names can be reused after replacement. - Separate TCP from UDP: the command uses
-t; UDP sessions do not have TCP’s established state and require a different query. - Protect diagnostics: addresses, ports, and process names can reveal internal topology. Handle captured output according to your access and retention policy.
- Do not assume a listening port is an active client: the state filter is what excludes listening-only sockets from the final result.
Frequently Asked Questions
Can this command inspect a container on another Docker host?
Not directly. Connect to the Docker host that runs the container, then execute the command there, using your organization’s approved remote-access method.
Does running ss change or interrupt connections?
No. It reads the socket table and reports the state; it does not close or reconfigure the sockets.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsHow can I check a short-lived connection that disappears before I can run the command?
Collect repeated snapshots during the event or use an approved connection-monitoring system; a single ss invocation cannot reconstruct past sockets.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




