Linux Commands Every Sysadmin Should Know
The essential Linux commands every sysadmin should know, grouped by task, with accurate examples for files, processes, and networking.
In this guide
- Why command-line fluency still matters
- Navigating the filesystem
- Working with files and directories
- Viewing and searching text
- Managing permissions and ownership
- Monitoring processes and resources
- Checking disk and storage
Quick answer: The Linux commands every sysadmin should know cover navigation (ls, cd, pwd), files and permissions (cp, mv, chmod, chown), text searching (grep, find, tail), process and resource monitoring (ps, top, df, free), service control (systemctl, journalctl), and networking (ss, ip, ssh). Mastering these lets you operate almost any Linux server confidently.
Why command-line fluency still matters
Most Linux servers run without a graphical interface, so the command line is not optional; it is the primary way you interact with the system. Fluency with a core set of commands is the single most transferable skill in systems administration, and it underpins nearly every operations, cloud, and DevOps role. The commands below are grouped by task, with accurate examples you can adapt. Treat destructive commands with respect, especially anything that deletes files.
Navigating the filesystem
Every session starts with knowing where you are and what is around you. pwd prints your current directory, cd changes directories, and ls lists contents. The flags on ls are worth memorizing.
pwd
cd /var/log
ls -lah
Here -l gives a long listing with permissions and sizes, -a shows hidden files, and -h makes sizes human-readable. To return to your home directory, cd with no argument works, and cd - jumps back to the previous directory.
Working with files and directories
Creating, copying, moving, and removing files are daily tasks. Use mkdir -p to create nested directories in one step, and be deliberate with rm.
mkdir -p /opt/app/config
cp -r /etc/nginx /etc/nginx.bak
mv report.txt /home/user/reports/
rm -i oldfile.txt
The -r flag makes cp recursive for directories, and -i on rm prompts before each deletion, a useful safety net. Avoid running rm -rf unless you are certain of the target, because it deletes recursively and without confirmation.
Viewing and searching text
Servers generate enormous log and configuration files, so reading and filtering text efficiently is essential. cat dumps a whole file, less pages through it interactively, and head and tail show the beginning or end. The -f flag on tail follows a file live, which is invaluable for watching logs.
tail -f /var/log/syslog
grep -rn "error" /var/log/
find /home -name "*.conf" -type f
grep searches text; here -r is recursive and -n shows line numbers. find locates files by criteria such as name and type. These two commands, combined with pipes, solve a huge share of daily investigation tasks. For example, counting matching lines is a common one-liner:
grep -c "Failed password" /var/log/auth.log
Managing permissions and ownership
Linux permissions control who can read, write, and execute files. chmod changes permission modes and chown changes ownership. Numeric modes are common: read is 4, write is 2, and execute is 1, added together per user class.
chmod 644 index.html
chmod +x deploy.sh
chown www-data:www-data /var/www/html
The mode 644 gives the owner read and write and everyone else read only, which is typical for web files. chmod +x makes a script executable. chown user:group sets both the owning user and group in one command.
| Numeric mode | Meaning | Common use |
|---|---|---|
| 644 | Owner read/write, others read | Regular files |
| 755 | Owner full, others read/execute | Directories, scripts |
| 600 | Owner read/write only | Private keys, secrets |
| 700 | Owner full, no access for others | Private directories |
Monitoring processes and resources
When a server is slow, you need to see what is consuming resources. ps aux lists all running processes, top shows a live, sortable view, and free -h reports memory usage in readable units. To stop a misbehaving process, use kill with its process ID, escalating to kill -9 only if a normal termination fails.
ps aux | grep nginx
top
free -h
kill 4821
A frequent pattern is piping ps aux into grep to find a specific process quickly. Remember that kill -9 forces termination without cleanup, so try a plain kill first to let the process shut down gracefully.
Checking disk and storage
Running out of disk space is a classic outage cause. df -h shows free space per filesystem, and du -sh summarizes the size of a directory. Combining them helps you find what is filling a disk.
df -h
du -sh /var/*
du -sh /var/log
The -s flag on du gives a summary total rather than listing every file, and -h makes it human-readable. When a partition is nearly full, these two commands quickly point you to the culprit directory.
Managing services and logs
Modern Linux distributions use systemd to manage services. systemctl starts, stops, and inspects services, while journalctl reads their logs. These have largely replaced older init scripts.
systemctl status nginx
systemctl restart nginx
systemctl enable nginx
journalctl -u nginx --since "1 hour ago"
status shows whether a service is running and recent log lines, restart cycles it, and enable makes it start at boot. journalctl -u filters logs to a single unit, and the --since option limits the time range, which keeps output manageable on busy systems.
Networking essentials
Diagnosing connectivity is a core sysadmin task. ip a shows network interfaces and addresses, ss -tulpn lists listening ports and the processes behind them, and ssh connects to remote machines. curl -I fetches just the HTTP headers from a URL, useful for checking a web service.
ip a
ss -tulpn
ssh [email protected]
curl -I https://example.com
The ss command has largely replaced the older netstat; the flags mean TCP, UDP, listening, process, and numeric. To copy a file to a remote host over SSH, scp uses similar syntax:
scp backup.tar.gz [email protected]:/opt/backups/
Archiving and transferring files
Backups, log rotation, and moving data between servers rely on archiving tools. tar bundles many files into a single archive and can compress them at the same time. The classic flags are worth committing to memory: create, gzip, verbose, and file.
tar -czvf logs-backup.tar.gz /var/log
tar -xzvf logs-backup.tar.gz
Here -c creates an archive, -x extracts one, -z applies gzip compression, -v prints each file, and -f names the archive file. A helpful memory aid for extraction is “eXtract Ze Vile Files.” Combined with scp or a scheduled job, tar forms the backbone of many simple backup routines.
Managing packages and updates
Installing software and applying security updates is a core responsibility, and the exact command depends on the distribution family. Debian and Ubuntu use apt, while Red Hat, Fedora, and their derivatives use dnf (the successor to yum). Keeping systems patched is one of the most important things a sysadmin does for security.
| Task | Debian / Ubuntu | RHEL / Fedora |
|---|---|---|
| Refresh package lists | apt update |
dnf check-update |
| Install a package | apt install nginx |
dnf install nginx |
| Apply updates | apt upgrade |
dnf upgrade |
| Remove a package | apt remove nginx |
dnf remove nginx |
These commands typically require administrative privileges, so you will usually prefix them with sudo, which runs a single command as the superuser without logging in as root directly.
Managing users and privileges
Servers are shared, so controlling who can log in and what they can do is essential. useradd creates accounts, passwd sets passwords, and usermod modifies accounts, for example adding a user to a group. Granting administrative rights is usually done by adding a user to a privileged group such as sudo or wheel.
sudo useradd -m -s /bin/bash deploy
sudo passwd deploy
sudo usermod -aG sudo deploy
The -m flag creates a home directory, -s sets the login shell, and -aG appends the user to a supplementary group without removing them from others. Forgetting the -a when using -G is a classic mistake that removes a user from all their other groups, so always include it when adding a group.
Scheduling recurring tasks
Automation on a single server often starts with cron, which runs commands on a schedule. Editing your personal crontab opens a file where each line defines a schedule and a command.
crontab -e
# Run a backup script every day at 2:30 AM
30 2 * * * /opt/scripts/backup.sh
The five time fields are minute, hour, day of month, month, and day of week, followed by the command to run. Listing your current jobs with crontab -l confirms what is scheduled. For quick system context, uptime shows how long the machine has been running and its load average, while uname -a reports the kernel and architecture.
Building real skill from here
Memorizing commands is a start, but real competence comes from combining them with pipes, redirection, and shell scripting to automate repetitive work. Practice on a spare machine or virtual server where mistakes are safe. These fundamentals are the bedrock of certifications such as those covered in our comparison of RHCSA vs RHCE Linux certifications, and they map directly onto the daily work described in our guide to becoming a Linux administrator. They are equally essential for higher-level roles: nearly every task in infrastructure as code assumes command-line comfort, and both the DevOps engineer and site reliability engineer paths treat this fluency as table stakes. Learn these commands well, then keep a personal reference of the ones you use most, and your speed on any Linux system will steadily grow.
Ready to earn your certification?
Boost eLearning offers Live Labs, a Pass Guarantee, and online, live virtual, and on-site delivery.