Free tools Windows power users keep installed
One-click scans. No signup required.
For a running Linux container, the direct command is docker exec <container> ss -tan state established. Replace <container> with the container name or ID. The command runs ss inside the container’s network namespace, lists TCP sockets numerically, and keeps only connections whose state is ESTAB.
Run the established-connection check
First confirm the target is running:
docker ps
Then execute the socket listing:
docker exec <container> ss -tan state established
For example:
docker exec web ss -tan state established
A typical result has columns similar to:
State Recv-Q Send-Q Local Address:Port Peer Address:Port
ESTAB 0 0 172.18.0.4:8080 172.18.0.2:49152
The local address and port belong to the container’s network namespace; the peer columns identify the remote endpoint as seen by that namespace. An empty result means no established TCP sockets matched at that moment. It does not prove that the application is idle forever, because connections can open or close immediately after the command returns.
What each ss option does
-tselects TCP sockets.-aasks for all TCP sockets, including listening and non-listening sockets. The state expression then limits the displayed rows to established connections.-nkeeps addresses and ports numeric, avoiding DNS and service-name lookups that can slow or alter the display.state establishedapplies the state filter. Linux’sss(8)examples use the same state-filtering form for established connections.
If you also need process attribution, try:
docker exec <container> ss -tanp state established
The -p option asks for the owning process. Names and PIDs are not guaranteed: a minimal process view, dropped capabilities, another user, or container security settings can hide them.
Useful filters for a live investigation
Show only IPv4 or IPv6
docker exec <container> ss -4tan state established
docker exec <container> ss -6tan state established
Use these when dual-stack output makes it difficult to identify which address family an application is using.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
Filter by a port
The ss filter language can narrow results to a destination or source port. To inspect established connections going to HTTPS:
docker exec <container> ss -tan state established '( dport = :443 )'
To inspect connections originating from local port 8080:
docker exec <container> ss -tan state established '( sport = :8080 )'
Keep the expression quoted so the shell passes its parentheses to ss rather than interpreting them.
Observe changes repeatedly
For a short investigation on a host that has watch installed:
watch -n 1 'docker exec web ss -tan state established'
This starts a new inspection every second. It is a polling view, not a connection history; use application logs or packet tracing when you need to know exactly when a connection was created or closed.
Why the command must run in the container’s network namespace
A container normally has its own network view. Running ss directly on the Docker host shows host sockets and may include unrelated containers, host services, and other processes. Published ports and NAT rules describe how traffic is forwarded; they are not a substitute for the container’s current established-socket list.
docker network inspect is useful for network names, endpoints, IP addresses, drivers, and configuration. It does not list live established TCP sockets. Use docker exec, or a host-side tool placed in the target namespace, for connection state.
When ss is not installed
Small images often omit diagnostic utilities. Docker’s exec command runs an executable that already exists in a running container; it does not install ss or netstat.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteUse an available utility
Check for a socket tool that your image already includes:
docker exec <container> sh -c 'command -v ss || command -v netstat'
If netstat is present, an established-TCP query is commonly:
Rank #3
docker exec <container> netstat -tan
Unlike the ss command above, this output may include listening and other states, so filter or read the State column carefully. Only use tools and package repositories approved for your image and organization; adding packages to a production image can change its contents and restart requirements.
Attach approved diagnostic tooling
Your platform team may provide a diagnostic container that can join the target container’s network namespace. The image needs a socket utility, and the operator needs permission to attach it. Verify the image provenance and namespace settings before using this method. Do not assume an arbitrary public image is trusted or that it can see another container’s processes.
Inspect the namespace from a Linux host
On a Linux Docker host, you can identify the container’s primary-process PID:
PID=$(docker inspect --format '{{.State.Pid}}' <container>)
printf '%sn' "$PID"
Docker’s runtime-metrics documentation describes using that PID and the /proc/<pid>/ns/net handle to enter the container’s network namespace, commonly through a named namespace and ip netns exec. The exact setup differs by distribution and runtime. A typical workflow is:
- Confirm that the PID is nonzero and that the container is running.
- Create or reference a network-namespace name that points to
/proc/$PID/ns/net, using your host’s approved procedure. - Run the host’s socket utility through
ip netns exec <name>, for exampleip netns exec <name> ss -tan state established. - Remove any temporary namespace link when the investigation is complete, and re-check the procedure after Docker or distribution upgrades.
This method requires host access, a socket utility installed on the host, and permission to access the process namespace. It is a Linux-host technique; Docker Desktop and non-Linux environments may implement networking differently.
Docker Compose and multiple instances
For a Compose service, run:
docker compose exec <service> ss -tan state established
Compose’s exec targets a running service container. If the service has multiple replicas, first list them:
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstalldocker compose ps
Then select the intended container instance and use docker exec with its generated name or ID. Otherwise, you may inspect one replica while troubleshooting another.
Common errors and fixes
| Symptom | Likely cause | Fix |
|---|---|---|
Container ... is not running |
The primary process has stopped. | Run docker ps -a, inspect logs and the exit status, then start the container only if that is appropriate. docker exec cannot operate on a stopped container. |
executable file not found or ss: not found |
The image does not contain ss, or its executable path is unavailable. |
Use an installed utility, an approved diagnostic container, or the host namespace method. Installing a package is an image-management decision, not something docker exec does automatically. |
| Permission denied or no process information | Container user, capabilities, proc settings, or security policy restrict socket/process visibility. | Retry only with an approved diagnostic identity or host-side method. Treat missing -p details as a permissions limitation, not proof that no process owns the socket. |
| No rows are returned | No TCP socket is established at that instant, the wrong container was selected, or traffic uses another protocol. | Confirm the container ID, check the application port and logs, run without the state filter to see listening sockets, and remember that UDP does not appear in a TCP query. |
| Host output does not match container output | The host command is showing a different network namespace or additional sockets. | Run the command with docker exec or enter the exact namespace identified from the container PID. |
| Compose command targets the wrong workload | Several replicas or similarly named services exist. | Use docker compose ps and inspect the specific container instance with its ID. |
Operational notes: accuracy, overhead and safety
- Point-in-time data: socket state can change between rows being read and the command completing. Repeat the check when diagnosing intermittent traffic.
- Low-impact inspection:
ssreads kernel socket tables and is generally suitable for occasional checks. High-frequency polling across many containers still creates process and output overhead, so use a sensible interval. - DNS and service names: keep
-nfor predictable, fast output. Name resolution can block or produce labels that obscure the actual port. - Security: connection endpoints can reveal internal topology, credentials may be present in command environments, and host namespace access is privileged. Limit output and access to authorized operators.
- Scope: this procedure is for TCP connections. Use an appropriate UDP-capable view when the application protocol is UDP, and inspect application metrics when you need request-level rather than socket-level information.
Or skip the browser setup
ScreenshotNeo is a website screenshot API, not a replacement for ss or Docker namespace inspection. If your incident also requires a visual capture of a web page, it can return a screenshot or PDF with one request. Before capture it accepts cookie-consent banners and removes more than 60 known consent platforms, newsletter popups and chat widgets. Bot checks, CAPTCHAs, blank pages, timeouts, failed loads and cache hits are not billed, and the response identifies the page verdict and billing status.
See the ScreenshotNeo API documentation for all options. A direct cURL request is:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
The same request in Python:
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
And in Node.js:
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
It also provides an MCP server with take_screenshot, get_page_info and capture_pdf tools for Claude, Cursor and other MCP clients. The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000. If that visual workflow is useful, create a free ScreenshotNeo account.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
FAQ
Does an established entry mean the application is healthy?
No. It only means the kernel currently considers the TCP handshake complete. The peer may be unresponsive, and an application can be failing while a connection remains open.
Best Value
- Docker, Docker Swarm, Docker Compose, Programmer, Developer, Coding, Programming, Software Engineer, Code, DevOps, Deploy, Deployment, Kubernetes, Salt, Puppet, Chef, Terraform, Container, AWS, Azure, Cloud, Geek, Funny, Computer, Software, Tech, IT
- Integration, Scrum, Compile, Compilation, Science, Bug, Debug, Python, Linux, Java, Javascript, Scala, Dotnet, Kotlin
- Lightweight, Classic fit, Double-needle sleeve and bottom hem
Can I use this command on a stopped container?
No. Docker can execute a command only while the container’s primary process is running. Start or replace the workload according to its deployment procedure before inspecting it.
Why are container IP addresses different from the host’s addresses?
The command runs in the container’s network namespace, where Docker assigns its own interfaces and addresses. Host NAT and published ports can present a different view.
Frequently Asked Questions
Can I use this command on a stopped container?
No. Docker can execute a command only while the container’s primary process is running.
Does an established socket prove the application is healthy?
No. It confirms TCP state at that instant, not application responsiveness or request success.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

