Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

For a first look at an unfamiliar Linux server, start with read-only commands: whoami, pwd, hostname, uname -a, uptime, df -h, free -h, ps aux, ip addr, and ss -tulpn. They show who you are, where you are, what system you are on, and how its storage, processes, and network look—without intentionally changing system state. Linux distributions and installed tools differ, so check local help before relying on an option.

How to get oriented and find help

Before running an administrative command, confirm the account and directory your shell is using. These checks can prevent mistakes caused by assuming you are logged in as a particular user or working in a particular location.

  • whoami prints the current account name.
  • pwd prints the current working directory.
  • hostname displays the system’s host name.
  • who lists users currently logged in, when supported and permitted.
  • history displays commands recorded in the current shell’s history.

Use man COMMAND to open the installed manual for a command, if one is available. Many commands also support COMMAND --help. Installed versions, options, and manual availability vary; consult the target server’s local documentation rather than assuming every Linux system behaves identically. The GNU Coreutils manual is a detailed reference for many common file and text utilities.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to read and search files

These commands help inspect configuration, output, and logs. Treat their contents as potentially sensitive: logs and configuration files may include usernames, addresses, tokens, or other private information.

  • cat FILE prints a file’s contents to the terminal. It is convenient for short files.
  • less FILE opens a file for paging through it, which is usually easier for long output.
  • head FILE shows the beginning of a file; tail FILE shows its end.
  • grep PATTERN FILE searches file text for matching lines.
  • find PATH searches a directory tree. Add a search expression appropriate to your goal, and check the installed manual for supported syntax.

These commands are useful for investigation, but reading a file does not establish that changing it is safe. Confirm what a configuration file controls and preserve the original before editing.

How to manage files without losing data

File operations are straightforward but can have lasting effects. Verify both the source and destination paths before copying, moving, overwriting, or removing anything.

  • cp SOURCE DESTINATION copies a file or directory. Directory-copy options vary; check cp --help or its manual before using them.
  • mv SOURCE DESTINATION moves or renames an item. A destination that already exists can affect the result.
  • mkdir DIRECTORY creates a directory.
  • rm FILE removes a file. Recursive removal can delete a directory tree; inspect the target carefully before using recursive or force options.
  • tar creates or extracts archives. Its options and behavior depend on the operation, so check the manual and confirm the archive and target paths.

The GNU manuals cover basic file operations and other Coreutils utilities, including removal and permission-changing tools. Do not use a destructive command merely because it appears in a copied example.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to check disk space

df and du answer different questions, so a directory-size result should not be mistaken for free space on a mounted filesystem.

  • df -h reports capacity and usage for mounted filesystems in human-readable units.
  • du -sh PATH estimates the space attributable to a path, summarizing it in human-readable units.

df reports filesystem space usage, while du estimates space used by files. Their figures need not match: they measure different things, and a directory-tree estimate is not a direct measurement of space consumed on the underlying device. See the GNU documentation for df and du.

How to inspect system activity and resources

Use inspection commands to understand a server’s current state before changing it. Their output and the processes visible to you can depend on the operating system, installed tools, and your permissions.

  • uptime shows how long the system has been running and provides load information.
  • uname -a prints system identity and kernel details.
  • ps aux lists processes in a commonly supported format; options and visibility can vary.
  • top displays changing process and resource information interactively.
  • free -h reports memory figures in human-readable units on common Linux installations.

Do not terminate a process based only on a name match. First identify what it does and whether it belongs to a service or workload you could interrupt.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to investigate network connectivity

Use network tools to distinguish local configuration, listening sockets, and reachability. They inspect different layers; one result alone may not establish that an application is healthy.

  • ip addr displays network interfaces and addresses.
  • ip route displays routing information.
  • ss -tulpn inspects listening and other sockets, including process details where permissions allow.
  • ping HOST sends reachability probes where the tool is installed and network policy permits them.

A failed ping does not by itself prove a service is down: a firewall or network policy may block ping while the service remains reachable by another method. Conversely, a successful ping does not confirm that an application is accepting connections. Availability of commands and access to process details may depend on installed packages, platform, and privileges.

How to check services and logs

On a system that uses systemd, inspect a service before considering a restart. Substitute the actual service unit name for SERVICE.

  1. systemctl status SERVICE checks the status of a systemd service unit and provides recent status details.
  2. journalctl -u SERVICE reads journal entries associated with that unit. Review the relevant time period and messages for clues about the problem.

systemctl is specific to systemd-based systems; other Linux installations may use a different service manager. The systemctl manual documents service-unit operations. Access to service state and logs can also depend on permissions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When to use sudo and other state-changing commands

sudo runs a command with administrative privileges when your account is authorized. Use it for a specific task that requires elevated access, not as a default prefix. More privilege raises the potential impact of a wrong path, unit, or option.

  • Inspect the target before using recursive deletion, changing permissions, or restarting a service.
  • Understand what a command will change and which users or workloads it may affect.
  • Avoid treating chmod 777 as a general permissions fix. Grant only the access needed for the intended users or processes.
  • Check command-specific documentation because flags and behavior can differ between implementations.

The GNU Coreutils documentation covers changing permissions and removing files.

First-look checklist for an unfamiliar server

Run these checks in order to gather basic information before making changes. Some commands or options may be absent, restricted, or behave differently on a particular distribution.

  1. whoami — identify the current account.
  2. pwd — confirm the working directory.
  3. hostname — identify the host.
  4. uname -a — inspect system and kernel identity.
  5. uptime — check running time and load information.
  6. df -h — review mounted filesystem capacity.
  7. free -h — review memory figures, if available.
  8. ps aux — inspect visible processes.
  9. ip addr — inspect interfaces and addresses.
  10. ss -tulpn — inspect sockets and, where permitted, associated processes.

For a specific service problem on a systemd host, use systemctl status SERVICE and then journalctl -u SERVICE to investigate its status and logs. Use the installed manuals or --help when a command is missing or an option does not work.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.