↑ ↓ select, Enter open, Esc close

Count TCP connections by state

user@server
ss -Htan | awk '{print $1}' | sort | uniq -c | sort -rn

Counts all TCP sockets grouped by their state. Many TIME-WAIT entries are normal on web servers, whereas a large number of SYN-RECV may indicate a SYN flood. For an overall summary without individual states, ss -s also works.

Also searched as

  • count tcp connections by state
  • too many time_wait connections
  • detect syn flood linux

Related one-liners

All in Network

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.