{"id":2000,"date":"2026-09-23T08:00:00","date_gmt":"2026-09-23T12:00:00","guid":{"rendered":"https:\/\/boostelearning.com\/?p=2000"},"modified":"2026-09-23T08:00:00","modified_gmt":"2026-09-23T12:00:00","slug":"linux-commands-every-sysadmin-should-know","status":"publish","type":"post","link":"https:\/\/boostelearning.com\/hi\/resources\/blog\/linux-commands-every-sysadmin-should-know\/","title":{"rendered":"Linux Commands Every Sysadmin Should Know"},"content":{"rendered":"<p><strong>Quick answer:<\/strong> The Linux commands every sysadmin should know cover navigation (<code>ls<\/code>, <code>cd<\/code>, <code>pwd<\/code>), files and permissions (<code>cp<\/code>, <code>mv<\/code>, <code>chmod<\/code>, <code>chown<\/code>), text searching (<code>grep<\/code>, <code>find<\/code>, <code>tail<\/code>), process and resource monitoring (<code>ps<\/code>, <code>top<\/code>, <code>df<\/code>, <code>free<\/code>), service control (<code>systemctl<\/code>, <code>journalctl<\/code>), and networking (<code>ss<\/code>, <code>ip<\/code>, <code>ssh<\/code>). Mastering these lets you operate almost any Linux server confidently.<\/p>\n<h2>Why command-line fluency still matters<\/h2>\n<p>Most Linux servers run without a graphical interface, so the command line is not optional; it is the primary way you interact with the system. Fluency with a core set of commands is the single most transferable skill in systems administration, and it underpins nearly every operations, cloud, and DevOps role. The commands below are grouped by task, with accurate examples you can adapt. Treat destructive commands with respect, especially anything that deletes files.<\/p>\n<h2>Navigating the filesystem<\/h2>\n<p>Every session starts with knowing where you are and what is around you. <code>pwd<\/code> prints your current directory, <code>cd<\/code> changes directories, and <code>ls<\/code> lists contents. The flags on <code>ls<\/code> are worth memorizing.<\/p>\n<pre><code>pwd\ncd \/var\/log\nls -lah<\/code><\/pre>\n<p>Here <code>-l<\/code> gives a long listing with permissions and sizes, <code>-a<\/code> shows hidden files, and <code>-h<\/code> makes sizes human-readable. To return to your home directory, <code>cd<\/code> with no argument works, and <code>cd -<\/code> jumps back to the previous directory.<\/p>\n<h2>Working with files and directories<\/h2>\n<p>Creating, copying, moving, and removing files are daily tasks. Use <code>mkdir -p<\/code> to create nested directories in one step, and be deliberate with <code>rm<\/code>.<\/p>\n<pre><code>mkdir -p \/opt\/app\/config\ncp -r \/etc\/nginx \/etc\/nginx.bak\nmv report.txt \/home\/user\/reports\/\nrm -i oldfile.txt<\/code><\/pre>\n<p>The <code>-r<\/code> flag makes <code>cp<\/code> recursive for directories, and <code>-i<\/code> on <code>rm<\/code> prompts before each deletion, a useful safety net. Avoid running <code>rm -rf<\/code> unless you are certain of the target, because it deletes recursively and without confirmation.<\/p>\n<h2>Viewing and searching text<\/h2>\n<p>Servers generate enormous log and configuration files, so reading and filtering text efficiently is essential. <code>cat<\/code> dumps a whole file, <code>less<\/code> pages through it interactively, and <code>head<\/code> and <code>tail<\/code> show the beginning or end. The <code>-f<\/code> flag on <code>tail<\/code> follows a file live, which is invaluable for watching logs.<\/p>\n<pre><code>tail -f \/var\/log\/syslog\ngrep -rn \"error\" \/var\/log\/\nfind \/home -name \"*.conf\" -type f<\/code><\/pre>\n<p><code>grep<\/code> searches text; here <code>-r<\/code> is recursive and <code>-n<\/code> shows line numbers. <code>find<\/code> locates files by criteria such as name and type. These two commands, combined with pipes, solve a huge share of daily investigation tasks. For example, counting matching lines is a common one-liner:<\/p>\n<pre><code>grep -c \"Failed password\" \/var\/log\/auth.log<\/code><\/pre>\n<h2>Managing permissions and ownership<\/h2>\n<p>Linux permissions control who can read, write, and execute files. <code>chmod<\/code> changes permission modes and <code>chown<\/code> changes ownership. Numeric modes are common: read is 4, write is 2, and execute is 1, added together per user class.<\/p>\n<pre><code>chmod 644 index.html\nchmod +x deploy.sh\nchown www-data:www-data \/var\/www\/html<\/code><\/pre>\n<p>The mode <code>644<\/code> gives the owner read and write and everyone else read only, which is typical for web files. <code>chmod +x<\/code> makes a script executable. <code>chown user:group<\/code> sets both the owning user and group in one command.<\/p>\n<table>\n<thead>\n<tr>\n<th>Numeric mode<\/th>\n<th>Meaning<\/th>\n<th>Common use<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>644<\/td>\n<td>Owner read\/write, others read<\/td>\n<td>Regular files<\/td>\n<\/tr>\n<tr>\n<td>755<\/td>\n<td>Owner full, others read\/execute<\/td>\n<td>Directories, scripts<\/td>\n<\/tr>\n<tr>\n<td>600<\/td>\n<td>Owner read\/write only<\/td>\n<td>Private keys, secrets<\/td>\n<\/tr>\n<tr>\n<td>700<\/td>\n<td>Owner full, no access for others<\/td>\n<td>Private directories<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Monitoring processes and resources<\/h2>\n<p>When a server is slow, you need to see what is consuming resources. <code>ps aux<\/code> lists all running processes, <code>top<\/code> shows a live, sortable view, and <code>free -h<\/code> reports memory usage in readable units. To stop a misbehaving process, use <code>kill<\/code> with its process ID, escalating to <code>kill -9<\/code> only if a normal termination fails.<\/p>\n<pre><code>ps aux | grep nginx\ntop\nfree -h\nkill 4821<\/code><\/pre>\n<p>A frequent pattern is piping <code>ps aux<\/code> into <code>grep<\/code> to find a specific process quickly. Remember that <code>kill -9<\/code> forces termination without cleanup, so try a plain <code>kill<\/code> first to let the process shut down gracefully.<\/p>\n<h2>Checking disk and storage<\/h2>\n<p>Running out of disk space is a classic outage cause. <code>df -h<\/code> shows free space per filesystem, and <code>du -sh<\/code> summarizes the size of a directory. Combining them helps you find what is filling a disk.<\/p>\n<pre><code>df -h\ndu -sh \/var\/*\ndu -sh \/var\/log<\/code><\/pre>\n<p>The <code>-s<\/code> flag on <code>du<\/code> gives a summary total rather than listing every file, and <code>-h<\/code> makes it human-readable. When a partition is nearly full, these two commands quickly point you to the culprit directory.<\/p>\n<h2>Managing services and logs<\/h2>\n<p>Modern Linux distributions use systemd to manage services. <code>systemctl<\/code> starts, stops, and inspects services, while <code>journalctl<\/code> reads their logs. These have largely replaced older init scripts.<\/p>\n<pre><code>systemctl status nginx\nsystemctl restart nginx\nsystemctl enable nginx\njournalctl -u nginx --since \"1 hour ago\"<\/code><\/pre>\n<p><code>status<\/code> shows whether a service is running and recent log lines, <code>restart<\/code> cycles it, and <code>enable<\/code> makes it start at boot. <code>journalctl -u<\/code> filters logs to a single unit, and the <code>--since<\/code> option limits the time range, which keeps output manageable on busy systems.<\/p>\n<h2>Networking essentials<\/h2>\n<p>Diagnosing connectivity is a core sysadmin task. <code>ip a<\/code> shows network interfaces and addresses, <code>ss -tulpn<\/code> lists listening ports and the processes behind them, and <code>ssh<\/code> connects to remote machines. <code>curl -I<\/code> fetches just the HTTP headers from a URL, useful for checking a web service.<\/p>\n<pre><code>ip a\nss -tulpn\nssh user@server.example.com\ncurl -I https:\/\/example.com<\/code><\/pre>\n<p>The <code>ss<\/code> command has largely replaced the older <code>netstat<\/code>; the flags mean TCP, UDP, listening, process, and numeric. To copy a file to a remote host over SSH, <code>scp<\/code> uses similar syntax:<\/p>\n<pre><code>scp backup.tar.gz user@server.example.com:\/opt\/backups\/<\/code><\/pre>\n<h2>Archiving and transferring files<\/h2>\n<p>Backups, log rotation, and moving data between servers rely on archiving tools. <code>tar<\/code> bundles many files into a single archive and can compress them at the same time. The classic flags are worth committing to memory: create, gzip, verbose, and file.<\/p>\n<pre><code>tar -czvf logs-backup.tar.gz \/var\/log\ntar -xzvf logs-backup.tar.gz<\/code><\/pre>\n<p>Here <code>-c<\/code> creates an archive, <code>-x<\/code> extracts one, <code>-z<\/code> applies gzip compression, <code>-v<\/code> prints each file, and <code>-f<\/code> names the archive file. A helpful memory aid for extraction is &#8220;eXtract Ze Vile Files.&#8221; Combined with <code>scp<\/code> or a scheduled job, <code>tar<\/code> forms the backbone of many simple backup routines.<\/p>\n<h2>Managing packages and updates<\/h2>\n<p>Installing software and applying security updates is a core responsibility, and the exact command depends on the distribution family. Debian and Ubuntu use <code>apt<\/code>, while Red Hat, Fedora, and their derivatives use <code>dnf<\/code> (the successor to <code>yum<\/code>). Keeping systems patched is one of the most important things a sysadmin does for security.<\/p>\n<table>\n<thead>\n<tr>\n<th>Task<\/th>\n<th>Debian \/ Ubuntu<\/th>\n<th>RHEL \/ Fedora<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Refresh package lists<\/td>\n<td><code>apt update<\/code><\/td>\n<td><code>dnf check-update<\/code><\/td>\n<\/tr>\n<tr>\n<td>Install a package<\/td>\n<td><code>apt install nginx<\/code><\/td>\n<td><code>dnf install nginx<\/code><\/td>\n<\/tr>\n<tr>\n<td>Apply updates<\/td>\n<td><code>apt upgrade<\/code><\/td>\n<td><code>dnf upgrade<\/code><\/td>\n<\/tr>\n<tr>\n<td>Remove a package<\/td>\n<td><code>apt remove nginx<\/code><\/td>\n<td><code>dnf remove nginx<\/code><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>These commands typically require administrative privileges, so you will usually prefix them with <code>sudo<\/code>, which runs a single command as the superuser without logging in as root directly.<\/p>\n<h2>Managing users and privileges<\/h2>\n<p>Servers are shared, so controlling who can log in and what they can do is essential. <code>useradd<\/code> creates accounts, <code>passwd<\/code> sets passwords, and <code>usermod<\/code> modifies accounts, for example adding a user to a group. Granting administrative rights is usually done by adding a user to a privileged group such as sudo or wheel.<\/p>\n<pre><code>sudo useradd -m -s \/bin\/bash deploy\nsudo passwd deploy\nsudo usermod -aG sudo deploy<\/code><\/pre>\n<p>The <code>-m<\/code> flag creates a home directory, <code>-s<\/code> sets the login shell, and <code>-aG<\/code> appends the user to a supplementary group without removing them from others. Forgetting the <code>-a<\/code> when using <code>-G<\/code> is a classic mistake that removes a user from all their other groups, so always include it when adding a group.<\/p>\n<h2>Scheduling recurring tasks<\/h2>\n<p>Automation on a single server often starts with <code>cron<\/code>, which runs commands on a schedule. Editing your personal crontab opens a file where each line defines a schedule and a command.<\/p>\n<pre><code>crontab -e\n# Run a backup script every day at 2:30 AM\n30 2 * * * \/opt\/scripts\/backup.sh<\/code><\/pre>\n<p>The five time fields are minute, hour, day of month, month, and day of week, followed by the command to run. Listing your current jobs with <code>crontab -l<\/code> confirms what is scheduled. For quick system context, <code>uptime<\/code> shows how long the machine has been running and its load average, while <code>uname -a<\/code> reports the kernel and architecture.<\/p>\n<h2>Building real skill from here<\/h2>\n<p>Memorizing commands is a start, but real competence comes from combining them with pipes, redirection, and shell scripting to automate repetitive work. Practice on a spare machine or virtual server where mistakes are safe. These fundamentals are the bedrock of certifications such as those covered in our comparison of <a href=\"\/resources\/blog\/rhcsa-vs-rhce-linux-certification\/\">RHCSA vs RHCE Linux certifications<\/a>, and they map directly onto the daily work described in our guide to <a href=\"\/resources\/blog\/how-to-become-a-linux-administrator\/\">becoming a Linux administrator<\/a>. They are equally essential for higher-level roles: nearly every task in <a href=\"\/resources\/blog\/what-is-infrastructure-as-code\/\">infrastructure as code<\/a> assumes command-line comfort, and both the <a href=\"\/resources\/blog\/how-to-become-a-devops-engineer\/\">DevOps engineer<\/a> and <a href=\"\/resources\/blog\/how-to-become-a-site-reliability-engineer\/\">site reliability engineer<\/a> paths treat this fluency as table stakes. Learn these commands well, then keep a personal reference of the ones you use most, and your speed on any Linux system will steadily grow.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The essential Linux commands every sysadmin should know, grouped by task, with accurate examples for files, processes, and networking.<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"bel_standfirst":"","bel_faq":"What are the most important Linux commands to learn first?|Start with navigation and file commands: ls, cd, pwd, cp, mv, and rm. Then add grep and find for searching, ps and top for processes, and systemctl for services. These cover most day-to-day sysadmin work.\nWhat is the difference between kill and kill -9?|A plain kill sends a termination signal that lets a process shut down gracefully, cleaning up as it exits. kill -9 sends SIGKILL, which forces immediate termination without cleanup. Use kill -9 only when a normal kill fails.\nHow do I check disk space on Linux?|Use df -h to see free space per filesystem in human-readable units. To find which directories are using the most space, use du -sh on a path, such as du -sh \/var\/* to summarize each subdirectory.\nWhat replaced netstat for checking ports?|The ss command has largely replaced netstat on modern systems. Running ss -tulpn lists TCP and UDP listening ports along with the process using each one, which is ideal for finding what is bound to a port.\nHow do I view logs for a specific service?|On systemd-based distributions, use journalctl -u followed by the service name, for example journalctl -u nginx. Add options like --since to limit the time range and keep the output manageable on busy servers.\nIs it safe to use rm -rf?|It is powerful and unforgiving. rm -rf deletes files and directories recursively without prompting, so a mistyped path can cause serious data loss. Double-check the target, and consider rm -i for interactive confirmation on important systems.","bel_outcomes":"","bel_audience":"","bel_outline":"","bel_exam":"","bel_livelabs":"","bel_duration":"","bel_exam_code":"","bel_level":"","bel_price":"","bel_rating":"","bel_reviews":"","bel_instructors":"","bel_image_credit":"","bel_result_num":"","bel_result_label":"","bel_customer":"","bel_industry":"","bel_credentials":"","bel_courses_taught":"","bel_meta_desc":"The essential Linux commands every sysadmin should know, grouped by task, with accurate examples for files, processes, and networking. \u2014 boostelearning.com","footnotes":""},"categories":[46],"tags":[],"class_list":["post-2000","post","type-post","status-publish","format-standard","hentry","category-linux"],"_links":{"self":[{"href":"https:\/\/boostelearning.com\/hi\/wp-json\/wp\/v2\/posts\/2000","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/boostelearning.com\/hi\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/boostelearning.com\/hi\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/boostelearning.com\/hi\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/boostelearning.com\/hi\/wp-json\/wp\/v2\/comments?post=2000"}],"version-history":[{"count":1,"href":"https:\/\/boostelearning.com\/hi\/wp-json\/wp\/v2\/posts\/2000\/revisions"}],"predecessor-version":[{"id":2194,"href":"https:\/\/boostelearning.com\/hi\/wp-json\/wp\/v2\/posts\/2000\/revisions\/2194"}],"wp:attachment":[{"href":"https:\/\/boostelearning.com\/hi\/wp-json\/wp\/v2\/media?parent=2000"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/boostelearning.com\/hi\/wp-json\/wp\/v2\/categories?post=2000"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/boostelearning.com\/hi\/wp-json\/wp\/v2\/tags?post=2000"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}