Showing posts with label lsof. Show all posts
Showing posts with label lsof. Show all posts

Sunday, April 19, 2009

lsof can be used in many ways for troubleshooting purposes

lsof is a very useful command. Is shows various opened files. You may use lsof with specific port,pid or process.When used in correct context,it will save your life in difficult troubleshooting sessions.

Suppose you want to see what are the various services running in you server. I know you will say netstat. But you may also use lsof -i -n.

lsof -i -n

-n for overriding dns resolution
Lets discuss some of other cases too.
-i:portno
lsof -i:389


Port 389 is used by ldap by default.
This will show all the services on this port. It will also show connection status too.
lsof -i:143 -n

-n will give ip address instead of fqdn
-p:pid
lsof -p:1234


There were some situation when some stale processes were hindering new processes to spawn. This switch will display all the files,connections,sockets opened by it.
We can confirm if the particular process is stale(before kill -9)
-c process_name
lsof -c dhcpd

This switch will show all the files(connection status,type) and many other regular info of this process.

what are the various resources a process is utilizing ?

There was one particular incidence when i am making changes in some conf file but its not taking effect.There were some cases when i am expecting spool directory's path in some other location but postfix is picking up some other location.
In nutshell, we want to see what are the files a particular daemon is using or opening or referring.
Lets be more specific.As i mainly deal with postfix, there are mainly two conf files, master.conf and main.conf. We are interested in knowing what are the files master process is using, i will issue following command to get this info

lsof -c master


it will show all the files,sockets,tcp connections attached to this process.

You may use other processes too to track them down.

Very useful in case you are running out of ideas what next to do if correct thing in correct place( as you think) is not taking place.

I was trying to clear spool directory but master was using different location. I was expecting it to be where it should be(during build i specified) but default postfix installation in OS was forcing different spool location(during booting).

Whole story is too big to mention here. Not in context too.