Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use lsof to discover which processes have files, directories, devices, or sockets open. The most useful starting commands are lsof /path/to/file for a pathname, lsof -p PID for a process, lsof -u USER for an account, and lsof -i for Internet sockets. Add filters deliberately: the default listing can be very large, and combining selectors changes whether results are alternatives or an intersection.

What lsof reports

The Linux manual summarizes the utility as “lsof – list open files.” Its definition of a file is broad. Besides regular files, output can describe directories, block and character devices, executable text, shared libraries, streams, and network files such as Internet, NFS, and UNIX-domain sockets. lsof associates those objects with the processes that opened them.

With no options, lsof examines active processes and prints every open item it can observe. That is useful for an overview but often produces pages of output. For troubleshooting, begin with the selection that matches your question: a path, PID, user, network family, or command.

Behavior and available fields vary between lsof implementations. This guide targets Linux; confirm platform-specific details in the installed lsof(8) manual. Visibility also depends on permissions and system configuration, so an unprivileged invocation is not a guarantee that every process will be shown.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Install lsof on your Linux distribution

lsof is normally supplied through your distribution’s package repositories. Package names and installation commands differ, so use your distribution’s package index and documentation rather than assuming one command works everywhere. After installation, check the local manual with man lsof and verify the executable with lsof -v if your build supports that option.

Find which process is using a file

Pass the pathname as an argument:

lsof /path/to/file

This reports processes with that path open. It is the direct answer to “Which process is using this file?” Use the exact path visible to the process; a different spelling, mount namespace, or symlink can produce different results. If the target is a directory, lsof can show files and objects associated with that directory or filesystem, but inaccessible entries may be omitted.

To obtain only process IDs, use -t:

lsof -t /path/to/file

The terse output is useful when feeding a PID into another command. Do not parse the normal aligned display by splitting on whitespace: filenames can contain spaces, and that format is intended for people, not scripts.

Inspect files opened by a process

Use a known PID

lsof -p 1234

Replace 1234 with the process ID. The result includes the process’s current directory, executable text, memory-mapped libraries, descriptors, and other open objects that lsof can inspect. Entries such as cwd, txt, and mem are descriptor categories associated with a process; they are not all ordinary numbered file descriptors.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use a command name

If you know the executable or command name but not its PID, use the command-selection form documented by your local manual (commonly -c followed by a command-name pattern). A command-name match is not the same as a pathname match: several processes can run the same command, and a displayed name can be truncated or differ from the executable path. When precision matters, identify the PID first and rerun with -p.

Find files opened by a user

lsof -u username

Replace username with the account name. This selects open files associated with processes owned by that user. It is useful for auditing a service account or finding what a login session has open. If you need to combine a user condition with another selector, read the local manual’s selection rules and use -a where an AND relationship is required.

Examine network sockets

List Internet sockets

lsof -i

-i selects Internet network files. Depending on the local name-service configuration, addresses and ports may be rendered as names or numbers. To investigate a particular protocol, address, port, or service, use the network-selection syntax documented in lsof(8); the exact expression determines how narrowly the result is filtered.

Include UNIX-domain sockets

lsof -i -U

-U selects UNIX-domain files. Combining it with -i displays both Internet and UNIX-domain socket information, which is helpful when a service communicates locally as well as over TCP or UDP.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

AND network and PID filters

lsof -i 4 -a -p 1234

This documented example selects IPv4 network files belonging to PID 1234. The -a option ANDs selection conditions; without the appropriate conjunction, multiple selection options can be interpreted as alternatives rather than an intersection. When a requested PID may have exited or may have no matching IPv4 socket, the manual documents:

lsof -Q -i 4 -a -p 1234

Here -Q handles the specified no-match conditions for the request. It is not a universal “ignore all errors” switch; consult the manual for the cases it covers.

Find unlinked files that still consume space

lsof +L1

An application can unlink a file while keeping its descriptor open. The directory entry disappears, but the process still holds the inode and its disk blocks remain allocated. The +L1 task pattern finds open files with a link count below one. lsof identifies the process and object; it does not free the space. Space is reclaimed only after every process closes the file (or is otherwise safely stopped), so investigate the owning service before taking action.

Find processes blocking an unmount

lsof /mnt

Replace /mnt with the mount point. This is the project’s documented approach for finding processes that keep a mount busy before umount. Check shells whose current directory is inside the mount, programs with open data files, and services using sockets or libraries from it. Results can be incomplete or slow for inaccessible or network filesystems; use appropriate administrative privileges where permitted and verify the mount and process namespaces involved.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Understand the default output

The human-readable listing is organized around process and file information. Common columns include:

  • COMMAND: the process command name.
  • PID: process identifier.
  • USER: account that owns the process.
  • FD: file-descriptor number or a category such as cwd, txt, or mem.
  • TYPE: the kind of object, such as a regular file, directory, device, or socket.
  • NAME: pathname, endpoint, device, or other object description.

Exact abbreviations, endpoint formatting, and additional columns are platform- and version-dependent. Treat the installed manual as authoritative rather than copying assumptions from an output sample on another system.

Produce script-friendly output

For automation, use field mode:

lsof -F pcufn /path/to/file

The identifiers in this example request process command (p), PID (c), user (u), file descriptor (f), and name (n) fields. Field-mode records are designed for programs and avoid the ambiguity of whitespace-aligned columns. Select only identifiers your script needs and read the field-output section of the local manual before relying on a field’s exact semantics. Names can contain spaces and other characters, so parse field boundaries according to the documented format.

A practical decision guide

Question Command What it selects
Which process uses this path? lsof /path/to/file Processes with the pathname open
What has this PID open? lsof -p 1234 Open objects associated with one process
What has this account open? lsof -u username Objects opened by processes owned by a user
Which Internet sockets exist? lsof -i Internet network files
Which IPv4 sockets belong to this PID? lsof -i 4 -a -p 1234 Intersection of IPv4 and PID selections
Which files were unlinked but remain open? lsof +L1 Open files whose link count is below one
What PIDs use this path? lsof -t /path/to/file PID-only output for composition
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting empty, missing, or confusing results

No rows appear

The process may have closed the object, the path may be spelled differently, or the process may be outside your visibility. Recheck the path, repeat the query promptly, and use permitted administrative privileges when policy allows. For a requested PID with no matching IPv4 network file, the documented -Q form can distinguish specified no-match cases.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The listing is enormous

Do not start with an unfiltered scan on a busy host. Narrow by pathname, PID, user, command, protocol, address, or port. Redirect output only after choosing a filter that answers the operational question.

A mount still will not unmount

Query the mount path and inspect cwd, regular files, memory mappings, and sockets. Network filesystems and permission boundaries can complicate discovery; confirm that you are examining the relevant host and namespace.

Socket names are not numeric

lsof may display service or host names according to name-service settings. Use the manual’s network-selection syntax and local name-resolution controls when you need numeric endpoint details.

A script breaks on filenames with spaces

Switch from the default display to -F and parse its documented field records. Never assume columns remain aligned or that a single whitespace split identifies the name.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Performance, permissions, and safe operations

Scanning every process and open object can be expensive on a large system, while path and PID queries are usually more focused. Run the narrowest query that answers the question and avoid repeatedly polling an unfiltered listing. Permissions can limit visibility, especially for processes owned by other users or protected kernel interfaces. Escalate privileges only according to your system policy.

lsof is observational: it reports relationships between processes and open objects. Stopping a process, deleting a file, or forcing an unmount is a separate administrative action. Verify the service, data, and recovery plan before acting on a PID returned by lsof.

Or skip the browser setup

If your workflow also needs a clean screenshot of a web page—for example, to attach visual evidence to an incident—ScreenshotNeo provides a single HTTP request instead of maintaining a browser. Its capture process accepts cookie or consent banners and removes more than 60 known consent platforms, newsletter popups, and chat widgets before the shot; bot checks, CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed. It also offers an MCP server with take_screenshot, get_page_info, and capture_pdf tools for Claude, Cursor, and other MCP clients.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo API documentation for the other 63 capture options, response headers, and formats. The free plan includes 1,000 screenshots each month with no card; paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Frequently Asked Questions

Does lsof show only regular disk files?

No. Its scope also includes directories, devices, executable text, libraries, streams, and network files such as Internet and UNIX-domain sockets.

What does the -a option do in lsof?

It ANDs selection criteria. For example, lsof -i 4 -a -p 1234 limits results to IPv4 network files belonging to PID 1234.

Can lsof close a file or delete an unlinked file?

No. It reports which process holds an object. Closing descriptors, stopping services, or reclaiming space requires a separate, carefully chosen administrative action.

Why should automation use -F?

The normal display is formatted for people and can contain spaces in names. -F emits documented field records that are safer for programmatic parsing.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.