Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For a running Linux container, the direct command is docker exec <container> ss -tan state established. Replace <container> with the container name or ID. The command runs ss inside the container’s network namespace, lists TCP sockets numerically, and keeps only connections whose state is ESTAB.

Run the established-connection check

First confirm the target is running:

docker ps

Then execute the socket listing:

docker exec <container> ss -tan state established

For example:

docker exec web ss -tan state established

A typical result has columns similar to:

State Recv-Q Send-Q Local Address:Port Peer Address:Port
ESTAB 0      0      172.18.0.4:8080   172.18.0.2:49152

The local address and port belong to the container’s network namespace; the peer columns identify the remote endpoint as seen by that namespace. An empty result means no established TCP sockets matched at that moment. It does not prove that the application is idle forever, because connections can open or close immediately after the command returns.

What each ss option does

  • -t selects TCP sockets.
  • -a asks for all TCP sockets, including listening and non-listening sockets. The state expression then limits the displayed rows to established connections.
  • -n keeps addresses and ports numeric, avoiding DNS and service-name lookups that can slow or alter the display.
  • state established applies the state filter. Linux’s ss(8) examples use the same state-filtering form for established connections.

If you also need process attribution, try:

docker exec <container> ss -tanp state established

The -p option asks for the owning process. Names and PIDs are not guaranteed: a minimal process view, dropped capabilities, another user, or container security settings can hide them.

Useful filters for a live investigation

Show only IPv4 or IPv6

docker exec <container> ss -4tan state established
docker exec <container> ss -6tan state established

Use these when dual-stack output makes it difficult to identify which address family an application is using.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Filter by a port

The ss filter language can narrow results to a destination or source port. To inspect established connections going to HTTPS:

docker exec <container> ss -tan state established '( dport = :443 )'

To inspect connections originating from local port 8080:

docker exec <container> ss -tan state established '( sport = :8080 )'

Keep the expression quoted so the shell passes its parentheses to ss rather than interpreting them.

Observe changes repeatedly

For a short investigation on a host that has watch installed:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
watch -n 1 'docker exec web ss -tan state established'

This starts a new inspection every second. It is a polling view, not a connection history; use application logs or packet tracing when you need to know exactly when a connection was created or closed.

Why the command must run in the container’s network namespace

A container normally has its own network view. Running ss directly on the Docker host shows host sockets and may include unrelated containers, host services, and other processes. Published ports and NAT rules describe how traffic is forwarded; they are not a substitute for the container’s current established-socket list.

docker network inspect is useful for network names, endpoints, IP addresses, drivers, and configuration. It does not list live established TCP sockets. Use docker exec, or a host-side tool placed in the target namespace, for connection state.

When ss is not installed

Small images often omit diagnostic utilities. Docker’s exec command runs an executable that already exists in a running container; it does not install ss or netstat.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use an available utility

Check for a socket tool that your image already includes:

docker exec <container> sh -c 'command -v ss || command -v netstat'

If netstat is present, an established-TCP query is commonly:

docker exec <container> netstat -tan

Unlike the ss command above, this output may include listening and other states, so filter or read the State column carefully. Only use tools and package repositories approved for your image and organization; adding packages to a production image can change its contents and restart requirements.

Attach approved diagnostic tooling

Your platform team may provide a diagnostic container that can join the target container’s network namespace. The image needs a socket utility, and the operator needs permission to attach it. Verify the image provenance and namespace settings before using this method. Do not assume an arbitrary public image is trusted or that it can see another container’s processes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Inspect the namespace from a Linux host

On a Linux Docker host, you can identify the container’s primary-process PID:

PID=$(docker inspect --format '{{.State.Pid}}' <container>)
printf '%sn' "$PID"

Docker’s runtime-metrics documentation describes using that PID and the /proc/<pid>/ns/net handle to enter the container’s network namespace, commonly through a named namespace and ip netns exec. The exact setup differs by distribution and runtime. A typical workflow is:

  1. Confirm that the PID is nonzero and that the container is running.
  2. Create or reference a network-namespace name that points to /proc/$PID/ns/net, using your host’s approved procedure.
  3. Run the host’s socket utility through ip netns exec <name>, for example ip netns exec <name> ss -tan state established.
  4. Remove any temporary namespace link when the investigation is complete, and re-check the procedure after Docker or distribution upgrades.

This method requires host access, a socket utility installed on the host, and permission to access the process namespace. It is a Linux-host technique; Docker Desktop and non-Linux environments may implement networking differently.

Docker Compose and multiple instances

For a Compose service, run:

docker compose exec <service> ss -tan state established

Compose’s exec targets a running service container. If the service has multiple replicas, first list them:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
docker compose ps

Then select the intended container instance and use docker exec with its generated name or ID. Otherwise, you may inspect one replica while troubleshooting another.

Common errors and fixes

Symptom Likely cause Fix
Container ... is not running The primary process has stopped. Run docker ps -a, inspect logs and the exit status, then start the container only if that is appropriate. docker exec cannot operate on a stopped container.
executable file not found or ss: not found The image does not contain ss, or its executable path is unavailable. Use an installed utility, an approved diagnostic container, or the host namespace method. Installing a package is an image-management decision, not something docker exec does automatically.
Permission denied or no process information Container user, capabilities, proc settings, or security policy restrict socket/process visibility. Retry only with an approved diagnostic identity or host-side method. Treat missing -p details as a permissions limitation, not proof that no process owns the socket.
No rows are returned No TCP socket is established at that instant, the wrong container was selected, or traffic uses another protocol. Confirm the container ID, check the application port and logs, run without the state filter to see listening sockets, and remember that UDP does not appear in a TCP query.
Host output does not match container output The host command is showing a different network namespace or additional sockets. Run the command with docker exec or enter the exact namespace identified from the container PID.
Compose command targets the wrong workload Several replicas or similarly named services exist. Use docker compose ps and inspect the specific container instance with its ID.

Operational notes: accuracy, overhead and safety

  • Point-in-time data: socket state can change between rows being read and the command completing. Repeat the check when diagnosing intermittent traffic.
  • Low-impact inspection: ss reads kernel socket tables and is generally suitable for occasional checks. High-frequency polling across many containers still creates process and output overhead, so use a sensible interval.
  • DNS and service names: keep -n for predictable, fast output. Name resolution can block or produce labels that obscure the actual port.
  • Security: connection endpoints can reveal internal topology, credentials may be present in command environments, and host namespace access is privileged. Limit output and access to authorized operators.
  • Scope: this procedure is for TCP connections. Use an appropriate UDP-capable view when the application protocol is UDP, and inspect application metrics when you need request-level rather than socket-level information.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

ScreenshotNeo is a website screenshot API, not a replacement for ss or Docker namespace inspection. If your incident also requires a visual capture of a web page, it can return a screenshot or PDF with one request. Before capture it accepts cookie-consent banners and removes more than 60 known consent platforms, newsletter popups and chat widgets. Bot checks, CAPTCHAs, blank pages, timeouts, failed loads and cache hits are not billed, and the response identifies the page verdict and billing status.

See the ScreenshotNeo API documentation for all options. A direct cURL request is:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

The same request in Python:

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

And in Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

It also provides an MCP server with take_screenshot, get_page_info and capture_pdf tools for Claude, Cursor and other MCP clients. The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000. If that visual workflow is useful, create a free ScreenshotNeo account.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

FAQ

Does an established entry mean the application is healthy?

No. It only means the kernel currently considers the TCP handshake complete. The peer may be unresponsive, and an application can be failing while a connection remains open.

Best Value
Docker Container Linux Devops Programming Coding T-Shirt
  • Docker, Docker Swarm, Docker Compose, Programmer, Developer, Coding, Programming, Software Engineer, Code, DevOps, Deploy, Deployment, Kubernetes, Salt, Puppet, Chef, Terraform, Container, AWS, Azure, Cloud, Geek, Funny, Computer, Software, Tech, IT
  • Integration, Scrum, Compile, Compilation, Science, Bug, Debug, Python, Linux, Java, Javascript, Scala, Dotnet, Kotlin
  • Lightweight, Classic fit, Double-needle sleeve and bottom hem

Can I use this command on a stopped container?

No. Docker can execute a command only while the container’s primary process is running. Start or replace the workload according to its deployment procedure before inspecting it.

Why are container IP addresses different from the host’s addresses?

The command runs in the container’s network namespace, where Docker assigns its own interfaces and addresses. Host NAT and published ports can present a different view.

Frequently Asked Questions

Can I use this command on a stopped container?

No. Docker can execute a command only while the container’s primary process is running.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Does an established socket prove the application is healthy?

No. It confirms TCP state at that instant, not application responsiveness or request success.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.