Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

lsof shows which processes have files open—including ordinary paths, devices, and network sockets. Start with lsof /path/to/file to find users of a path, lsof -p 1234 to inspect a process, or lsof -i to look at Internet sockets. Add filters to make the results useful, and use -a when you need selection criteria to match together.

What lsof lists

The name means “list open files.” In the Linux lsof(8) manual, “file” includes more than a regular file on disk: lsof can report directories, devices, executable text references, libraries, streams, and network files such as Internet, NFS, and UNIX domain sockets. Its output connects process details with the file-related items those processes have open.

Run lsof without options to list open files across active processes. On a busy system, that may produce a large result; a path, process ID, user, or socket filter is usually a more practical starting point.

Find processes using a path

Give lsof the path you want to investigate:

lsof /path/to/file

Replace /path/to/file with the path of interest. The output identifies processes that have that path open, subject to what the current user is allowed to see and what the system can report. If no entry appears, that does not by itself prove that no process has a related file open: the path may not match the open item as expected, or permissions and system configuration may limit visibility.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To look for processes holding files under a mount point, query the mount path, for example:

lsof /mnt

This can help identify processes that may be keeping a mount busy before an unmount. Inaccessible paths and network filesystems can complicate results, so treat an empty result as a clue rather than a universal guarantee.

Inspect a process or user

Files open by a known PID

Use -p followed by the process ID:

lsof -p 1234

Replace 1234 with the PID you want to inspect. This selects files associated with that process; it is not restricted to ordinary disk files.

Files open by a named command

To select by command name, use the command selector:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
lsof -c command

Substitute the command name for command. For exact matching rules and how the selector behaves on your installed version, consult its lsof(8) manual.

Files open by a user

Use -u followed by the account name:

lsof -u username

This is useful when investigating activity associated with an account rather than one process. A regular user’s view may not include every process or file on the system. Where appropriate, an administrator can run the query with elevated privileges, but access should follow the system’s policies.

Examine network sockets

Internet sockets

Use -i to select Internet network files:

lsof -i

To narrow a network query, use the protocol, address, port, or process selection syntax documented by the installed manual. For example, this asks for TCP entries on port 443:

lsof -iTCP:443

Network names and endpoint details shown in output can depend on the system and its configuration. Check the manual for the accepted network-selection forms rather than assuming that a displayed service name corresponds to a particular port.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

UNIX domain sockets

Use -U to select UNIX domain files. You can request both Internet and UNIX domain files with:

lsof -i -U

These are different socket categories; choose the one that matches the connection you are investigating.

Combine filters without changing the question

Multiple selection criteria do not always mean “match all of these.” When the goal is to find only IPv4 network files belonging to one PID, the manual’s example combines the criteria with -a:

lsof -i 4 -a -p 1234

Here, -i 4 selects IPv4 network files and -p 1234 selects a process; -a asks lsof to AND the selections. Without it, combined selectors can produce a broader result than intended. Whenever a query combines filters, check the manual’s selection-option rules and confirm that the result represents the intersection you want.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Find an unlinked file that is still open

A process can keep a file open after its directory entry has been removed. The pathname is no longer available in the ordinary way, but the open reference can remain until the process releases it. To look for open files with a link count below one, use:

lsof +L1

This identifies candidates; it does not close them or reclaim space itself. Releasing the file requires the responsible process to close it, which may mean having the application finish its work or managing the process according to your operational requirements.

Read the output

The default display is formatted for people. Common columns include the command, PID, user, file descriptor or descriptor category, file type, and name. A descriptor such as a number is not the only possible value: entries like cwd, txt, and mem describe process-associated items rather than ordinary numbered descriptors. Exact meanings and platform-dependent values belong to the installed lsof(8) manual.

Use the displayed name and process details to decide what to investigate next; do not assume every row is a regular file that can be removed. For example, a row can describe a current working directory, executable text, or a socket.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use field output in scripts

For automation, use -F and request only the fields your script needs. This example requests command, PID, user, descriptor, type, and name fields:

lsof -Fpcuftn /path/to/file

Field output uses identifiers such as p for PID and n for name; consult the manual’s field-output section for the complete format and field definitions. Parse those documented records instead of splitting the default aligned display on whitespace: filenames can contain spaces, and the human-readable columns are not a stable scripting interface.

Request process IDs only

For a path query where only matching PIDs are needed, use -t:

lsof -t /path/to/file

This can be useful when composing a workflow that consumes process IDs. Before using the result to take action, verify what the command will affect; a PID-only result carries less context than the full listing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Handle no-match results and visibility limits

A query can return no matching entries because the item is not open, because a requested process does not exist, or because the selection criteria do not match. Permissions and platform configuration can also affect what is visible. The manual documents -Q for specified no-match cases, not as a general switch that suppresses every error.

For example, it gives this form when a requested PID may not exist or may have no matching IPv4 network files:

lsof -Q -i 4 -a -p 1234

Use -Q only for the documented no-match behavior relevant to your query. It does not make inaccessible processes visible or turn an otherwise invalid invocation into a successful one.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshoot common lsof questions

“Which process is using this file?”

Start with lsof /path/to/file. If your workflow needs the manual’s specified no-match handling, check its path-query guidance for -Q. Confirm that you supplied the path you intend to query and have sufficient permission to see relevant processes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

“Why is umount blocked?”

Query the mount path, such as lsof /mnt, and investigate any listed processes before taking action. A missing result does not settle the question in every environment, especially when access restrictions or network filesystems are involved.

“What is using the network?”

Begin with lsof -i, then narrow by the protocol, address, port, or PID using the installed manual’s network-selection syntax. Use -U instead when you need UNIX domain files.

“Why did a combined query return too much?”

Review whether the selection criteria need to be ANDed. The manual’s IPv4-for-one-PID form is lsof -i 4 -a -p 1234; check the selection rules when adding further options.

“Why is the output empty or incomplete?”

Check the pathname and selectors, whether the PID still exists, and whether your account can inspect the relevant process. For no-match cases covered by the manual, -Q may be appropriate; it is not a universal visibility or error-suppression option.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Installation and platform notes

Use your Linux distribution’s package index to find its lsof package and installation instructions; package-manager commands are not interchangeable across distributions. The lsof project describes support across Linux and other Unix-like systems, but this guide focuses on Linux. Option behavior and output details may differ by implementation or version, so the manual installed on the machine you are troubleshooting is the most relevant reference. See the lsof project overview and its tutorial for additional project documentation.

Or skip the browser setup

For a separate task—capturing a website as an image or PDF—ScreenshotNeo offers a website screenshot API and MCP server. It does not replace lsof or inspect Linux processes. Its API can accept one GET request and return a screenshot or PDF; the options include full-page capture, element selection, device and viewport settings, custom CSS and JavaScript, and PDF settings. The API parameter names used by other screenshot APIs also work, which can help when switching.

One-call example with cURL: see the ScreenshotNeo API documentation for setup and options.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Cookie and consent banners are accepted like a visitor and removed along with 60+ known consent platforms, newsletter popups, and chat widgets; each cleanup step can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits cost nothing, and response headers identify the page verdict and billing status. An MCP server provides take_screenshot, get_page_info, and capture_pdf tools for AI agents using Claude, Cursor, or another MCP client. The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 shots.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Sign up for ScreenshotNeo’s free plan to get 1,000 screenshots a month with no card.

Frequently Asked Questions

Can lsof close a file or stop the process using it?

No. lsof reports open-file information; it does not close the file or stop its process. The process or application must release the open reference.

Does lsof show only regular files?

No. It can report directories, devices, process-associated items, and network files such as Internet and UNIX domain sockets.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.