Find out who is hogging your ephemeral ports before your app crashes
Networking & Firewall (Ss/Netstat/Iptables/Nftables/Curl)
Find out who is hogging your ephemeral ports before your app crashes
🧩 The Challenge
Dealing with a production app that randomly drops connections because you’ve exhausted all your local ports is a nightmare. I’ve spent way too long staring at logs wondering why the kernel was throwing connection resets for no apparent reason.
💡 The Fix
Use the socket statistics tool to count the active connections by state and local address so you can see if your app is leaking connections instead of closing them properly. You’ll quickly identify which service is the culprit.
ss -tanp | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -nr
⚙️ Why It Works
This pipes the raw socket list into a quick counter that groups connections by remote host, helping you spot the one PID creating thousands of sockets at once. It’s way faster than waiting for a netstat dump to hang your terminal.
🚀 Pro-Tip: Always pipe that into head to instantly see the top offending host.
Linux Tips & Tricks | © ngelinux.com | 9/23/2026
