Complete ss / netstat commands reference — 55 commands across 3 categories. Quick reference cheat sheet for Linux.
ss is the modern replacement for netstat on Linux — it reads socket state directly from the kernel, so it is faster and shows more — and its options are designed to be stacked into short strings such as ss -tulpn. The table lists the options and filter syntax from the manual; the notes explain the handful of combinations that answer nearly every "what is listening" and "who is connected" question.
| Shortcut | Action |
|---|---|
| ss -h | Show summary of options |
| ss -V | Output version information |
| ss -H | Suppress header line |
| ss -Q | Suppress sending and receiving queue columns |
| ss -O | Print each socket's data on a single line |
| ss -n | Do not try to resolve service names |
| ss -r | Try to resolve numeric address/ports |
| ss -a | Display both listening and non-listening (for TCP this means established connections) sock |
| ss -l | Display only listening sockets (these are omitted by default) |
| ss -B | Display only TCP bound but inactive (not listening, connecting, etc.) sockets (these are o |
| ss -o | Show timer information |
| ss -e | Show detailed socket information |
| ss -m | Show socket memory usage |
| ss -p | Show processes using sockets |
| ss -T | Show threads using sockets |
| ss -i | Show internal TCP information |
| ss --tos | Show ToS and priority information |
| ss --cgroup | Show cgroup information |
| ss --tipcinfo | Show internal tipc socket information |
| ss -K | Attempts to forcibly close sockets |
| ss -s | Print summary statistics |
| ss -E | Continually display sockets as they are destroyed |
| ss -Z | As the -p option but also shows process security context |
| ss -z | As the -Z option but also shows the socket context |
| ss -N NSNAME | Switch to the specified network namespace name |
| ss -b | Show socket classic BPF filters (only administrators are allowed to get this information) |
| ss -4 | Display only IP version 4 sockets (alias for -f inet) |
| ss -6 | Display only IP version 6 sockets (alias for -f inet6) |
| ss -0 | Display PACKET sockets (alias for -f link) |
| ss -t | Display TCP sockets |
| ss -u | Display UDP sockets |
| ss -d | Display DCCP sockets |
| ss -w | Display RAW sockets |
| ss -x | Display Unix domain sockets (alias for -f unix) |
| ss -S | Display SCTP sockets |
| ss --vsock | Display vsock sockets (alias for -f vsock) |
| ss -M | Display MPTCP sockets |
| ss --inet-sockopt | Display inet socket options |
| ss -f FAMILY | Display sockets of type FAMILY |
| ss -A QUERY | List of socket tables to dump, separated by commas |
| ss -D FILE | Do not display anything, just dump raw information about TCP sockets to FILE after applyin |
| ss -F FILE | Read filter information from FILE |
| ss --bpf-maps | Pretty-print all the BPF socket-local data entries for each socket |
| ss --bpf-map-id=MAP_ID | Pretty-print the BPF socket-local data entries for the requested map ID |
| Shortcut | Action |
|---|---|
| {dst|src} [=] HOST | Test if the destination or source matches HOST |
| {dport|sport} [OP] [FAMILY:]:PORT | Compare the destination or source port to PORT |
| dev [=|!=] DEVICE | Match based on the device the connection uses |
| fwmark [=|!=] MASK | Matches based on the fwmark value for the connection |
| cgroup [=|!=] PATH | Match if the connection is part of a cgroup at the given path |
| autobound | Match if the port or path of the source address was automatically allocated (rather than e |
| Shortcut | Action |
|---|---|
| ss -t -a | Display all TCP sockets |
| ss -t -a -Z | Display all TCP sockets with process SELinux security contexts |
| ss -u -a | Display all UDP sockets |
| ss -x src /tmp/.X11-unix/* | Find all local processes connected to X server |
| ss -a -A 'all,!tcp' | List sockets in all states from all socket tables but TCP |
Most invocations combine a socket-type letter with a state option: ss -l shows only listening sockets and ss -a shows all, while ss -t -a and ss -u -a restrict to TCP and UDP. Add ss -n to skip DNS and service-name lookups (faster and less confusing) and ss -p to show the owning process and PID, which usually needs root. The result, ss -tulpn, is the netstat replacement everyone memorises: every listening TCP and UDP port with the program behind it. ss -s prints summary counts by state, which is a quick health check on a busy server.
Rather than piping to grep, ss accepts filter expressions after the options. {dst|src} [=] HOST matches by address — ss -t dst 10.0.0.5 — and {dport|sport} [OP] [FAMILY:]:PORT matches by port, with operators such as = and >: ss -t sport = :22. State filters go before the expression, ss -t state established or state time-wait, and answer "how many connections are stuck". ss -4 and ss -6 restrict to one IP family, and ss -x with a path pattern finds Unix-socket clients, as in the X server example in the table.
ss -i prints internal TCP information per connection — congestion window, RTT, retransmits — which settles quickly whether a slow transfer is a network problem or an application one. ss -o shows timers such as keepalive and retransmission countdowns, ss -m socket memory, and ss -e extended details including the socket's inode. ss -E watches sockets as they are destroyed, and ss -K forcibly closes sockets matching a filter (kernel support required), which is occasionally the only way to clear a stuck connection without restarting the service.
ss -tulpn: TCP and UDP listening sockets, numeric, with process names. The letters are the same.
ss -t state established '( dport = :443 or sport = :443 )', or simply ss -t sport = :443 for the local side.
The -p option needs permission to read other users' processes; run it with sudo.
ss -s gives totals per state. For one state, ss -t state time-wait | wc -l.
Open your assistant with this page preloaded as the source — great for follow-up questions like "which of these work in other apps?"