To find the process behind a Linux port, start with ss to identify the socket, use lsof to cross-check it or get its PID, then inspect that PID with ps. Check the protocol, listening state, local address, and command before taking action: a port listing alone does not establish that a service is safe to stop or reachable from outside the host.
1. Check which socket is listening with ss
For a TCP listener on port 8080, run:
sudo ss -ltnp 'sport = :8080'
-lshows listening sockets.-tselects TCP sockets.-nkeeps addresses and port numbers numeric.-prequests process information.sport = :8080filters for the local source port.
sudo may reveal process details that your user cannot see, but use it only when you are authorized to inspect the system. Check man ss for the options and filter syntax supported by the installed version.
As an Amazon Associate I earn from qualifying purchases.
For UDP, query UDP sockets rather than assuming a TCP lookup covers them. If you are looking for a connection that is not listening, remove the listening-only condition and choose the socket state and protocol relevant to your question. “Using a port” can mean a listener or another kind of socket.
Free tools Windows power users keep installed
One-click scans. No signup required.
2. Cross-check the port or get its PID with lsof
lsof reports open files, including network sockets. To see readable details for Internet sockets using port 8080, run:
#1 Best Overall
sudo lsof -nP -i :8080
Here, -i :8080 selects Internet sockets by port, while -nP avoids resolving hostnames and converting port numbers to service names. For PID-only output, use:
lsof -t -i :8080
The -t option requests terse output containing process identifiers. Use man lsof to check the installed version’s port-filtering details and options.
3. Inspect the process behind a PID with ps
Once a socket lookup gives you a PID, substitute it for 1234 here:
ps -p 1234 -o pid,user,args
This displays the PID, owning user, and visible command arguments. ps provides process context; it does not identify which process owns a socket by itself. Command arguments can help identify an application, but they are not always a complete description of how a service is managed. Check man ps for local field and option details.
4. Interpret the result before changing anything
Compare the protocol and socket state with the question you are trying to answer, then check the local address, PID, and process command. The bind address affects reachability: a loopback-only listener is limited to the host’s loopback interface, whereas a wildcard bind can listen on multiple local interfaces. A port number by itself does not tell you whether remote machines can connect; network and firewall configuration also matter.
Do not terminate a process just because it appears in the listing. First identify the owning application or service and decide whether stopping it is appropriate. If it needs to be stopped, prefer the service manager or the application’s normal shutdown procedure over terminating it blindly.
Rank #4
5. If the commands show no result
An empty result is a clue to investigate, not conclusive proof that no process owns the port. Check these possibilities:
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware match- Protocol: The socket may be UDP rather than TCP, or vice versa.
- State: You may be filtering for listeners when the socket is established or in another state.
- Filter: Verify the port and command syntax, and consult the installed man page.
- Permissions: The current user may not be able to see process details. The
lsofmanual describes access warnings and errors; authorized elevated privileges may change what is visible. - Namespace or container: The command may be running in a different network namespace from the socket you are investigating. Check from the relevant host, container, or namespace.
- Timing: A short-lived socket may disappear between checks.
Which command should you use first?
| Command | Best role in this workflow | Useful detail |
|---|---|---|
ss |
Socket-first inspection | Can filter by protocol, state, and port, and request process information. |
lsof |
Open-file and socket cross-check | Can select Internet sockets by port; -t requests PID-only output. |
ps |
Process inspection after finding a PID | Shows selected process fields, such as PID, user, and arguments; does not perform the socket lookup. |
These commands provide complementary views rather than interchangeable guarantees. Results depend on permissions, timing, and the system or namespace being inspected. The examples are for Linux; distributions may ship different versions or options, so check man ss, man lsof, and man ps on the machine you are using.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




