↑ ↓ select, Enter open, Esc close

Count web server connections per IP address

user@server
ss -Htn state established '( sport = :80 or sport = :443 )' | awk '{print $4}' | rev | cut -d: -f2- | rev | sort | uniq -c | sort -rn | head -20

Lists all established TCP connections to the web ports, cuts off the remote port number and counts the connections per IP. The addresses with the most simultaneous connections appear at the top. Useful when the server suddenly slows down and a crawler or attacker is suspected.

Note: If a reverse proxy or CDN sits in front, its addresses appear instead of the real visitors.

Also searched as

  • count connections per ip linux
  • find ip with most connections
  • server slow check for ddos

Related one-liners

All in Network

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.