Find a Process's Open Log Files with pslog
You will finish with a quick way to see which open file descriptors of a process point to paths ending in log. This is useful when a daemon has been running for a while and you need to identify the file it is writing, without changing the process or its configuration. The examples use pslog from psmisc 23.7, installed here as package version 23.7-1build1.
The route
Jump straight to the step you need, or tick off Done means at the end.
Allow about ten minutes. You need a shell, the psmisc package, and a process ID to inspect. The normal command is unprivileged. Access to another user's /proc/PID/fd directory can be restricted by the kernel or mount options, in which case use an authorised account only where that is appropriate for your system.
1. Check the installed command
Confirm which executable and package version you are about to use. These checks do not alter the process or the filesystem:
$ command -v pslog
/usr/bin/pslog
$ dpkg-query -W -f='${Package} ${Version}\n' psmisc
psmisc 23.7-1build1
$ pslog -V
pslog (PSmisc) 23.7
Copyright (C) 2015-2017 Vito Mule'.
The version output continues with the programme's licence and warranty text. The useful detail here is the reported PSMisc version. Package versions and the exact path can differ on another distribution.
Checkpoint
Proceed only when command -v points to the executable you intended to run and the version is known.
2. Choose a process ID
Use ps or another trusted source to identify the target. A harmless first test is the current shell's parent process, if it is visible to your account:
$ printf 'shell PID: %s\n' "$BASHPID"
shell PID: 815406
$ ps -p "$BASHPID" -o pid=,comm=,args=
815406 bash -c ...
Replace the example number with the PID from your own output. Do not guess a PID from a log file name. PIDs are reused, so identify the process shortly before inspecting it. If you already know a service, verify its identity first:
$ ps -p 12345 -o pid=,comm=,args=
12345 example-daemon /usr/sbin/example-daemon --config /etc/example.conf
There is no need to stop the process. pslog reads the process's file-descriptor directory; it does not send a signal, close a descriptor, rotate a file or change a service.
3. Run pslog for one PID
Pass the verified numeric PID as the only ordinary argument:
$ pslog 12345
Pid no 12345:
Log path: /var/log/example-daemon.log
Each reported path is the target of an open descriptor whose target name ends in log. The output does not show every file the process can access, every file it has ever opened, or every logging destination configured for the service. It is an observation of open descriptors at the instant of the scan.
A process can have more than one matching descriptor, so treat each Log path: line as a separate result. A process with no matching descriptor normally produces just its PID heading and no log path. That is a valid result, not proof that the process never logs. It may log to journald, a socket, standard output, a file whose name does not end in log, or a descriptor that is not visible to your account.
Checkpoint
Copy the reported path and compare it with the service's documented logging configuration before opening, truncating or replacing anything.
4. Use the /proc form when it helps
The installed program accepts either a number or a path beginning with /proc/. These two forms inspect the same descriptor directory:
$ pslog 12345
Pid no 12345:
Log path: /var/log/example-daemon.log
$ pslog /proc/12345
Pid no /proc/12345:
Log path: /var/log/example-daemon.log
The numeric form is shorter and usually clearer in a shell script. The /proc/ form can make the kernel interface visible while you are troubleshooting. It still needs a live process directory, and the PID can disappear between choosing it and scanning it.
5. Understand permissions and failures
Inspecting your own process is normally straightforward. For a process owned by another account, the command may fail while opening /proc/PID/fd:
$ pslog 1
opendir: Permission denied
The exact error depends on the host's procfs privacy settings and permissions. First confirm the target and your account. Do not respond by making /proc broadly readable or weakening service isolation. If your operational role permits it, use the approved administrative procedure for that host; otherwise ask the owner of the service to perform the check.
An exited or nonexistent PID produces a different directory error:
$ pslog 999999999
opendir: No such file or directory
A non-zero status is the useful signal for automation. Check it immediately:
$ if pslog 12345; then
> echo 'descriptor scan completed'
> else
> echo 'descriptor scan failed' >&2
> fi
Do not parse a missing Log path: line as an error without considering the process's logging design. Conversely, do not treat the PID heading alone as evidence that the service has no logs.
6. Avoid two easy traps
First, the manual synopsis shows pid ..., but the installed 23.7 implementation uses the first process argument for its scan. Keep one PID per invocation when writing a check or an incident note:
$ for pid in 12345 12346; do
> pslog "$pid" || echo "pslog failed for $pid" >&2
> done
This also gives each result an unambiguous heading. Do not assume that writing pslog 12345 12346 will produce two complete reports on this installed version.
Second, pslog is read-only, but the path it reveals may be sensitive. Avoid pasting log paths, service names or command lines into public incident reports without checking their contents and handling requirements. Reading the path does not grant permission to read the file itself.
7. Finish with a verification record
Record the command, the PID, the process identity and the time of the scan. Then repeat the scan if the service is busy or rotates logs, because descriptors can change while the process remains alive:
$ date --iso-8601=seconds
2026-09-26T16:00:00+01:00
$ ps -p 12345 -o pid=,comm=
12345 example-daemon
$ pslog 12345
Pid no 12345:
Log path: /var/log/example-daemon.log
No undo step is required. The commands only inspect procfs and report what they find. If you changed a service or log configuration while following up, that is a separate operation with its own rollback plan; pslog itself makes no persistent change.
Done means
- You verified the installed
pslogbinary and psmisc version. - You confirmed the target PID's process identity immediately before the scan.
- You understand that results are open descriptor targets ending in
log, not a complete logging inventory. - You checked the exit status and can distinguish no matches from a permission or missing-PID failure.
- You used one PID per invocation on psmisc 23.7 and kept any reported paths appropriately private.