lsof - list open files
lsof [-p PID] [-i [:PORT]] [-u USER] [+L1] [-t] [path]
Options you will use
-p PID- Files opened by this process.
-i [:PORT]- Network sockets, optionally on one port. Needs root to see other users.
-u USER- Files opened by this user.
+L1- Files with a link count below 1: deleted, but still held open. The disk-space smoking gun.
-t- Terse: PIDs only, for piping into kill.
-a- AND the selections (by default -p and -d are ORed).
-d FD- Only these file descriptors: -d 214, -d 0-2, -d txt.
-n- Do not resolve IP addresses to host names (much faster).
+f -- PATH- Treat PATH as a file system: every open file on that mount.
Examples
$ sudo lsof -i :8080who is listening on that port
$ sudo lsof +L1deleted files still eating disk
Taught in
Try lsof in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.