Command library / systemctl
systemctl
Inspect and control system services
The front end to systemd, which starts and supervises almost everything on a modern Linux host. For a defender it answers two questions quickly: is this service healthy right now (status shows its state and latest log lines), and what is set to start automatically at boot, which is one of the first places to look for persistence.
Practice systemctlUsage
Options and flags
commandwhat to do: status, is-enabled, list-units, list-unit-files…
unitthe service (unit) it applies to, e.g. nginx or nginx.service
-t, --typeTYPEonly units of this type, e.g. service or timer
--stateSTATEonly units in this state, e.g. running, failed or enabled
--no-pagerprint everything at once instead of opening a pager
Examples
systemctl status nginxIs nginx running? Shows its state, main PID and latest log lines.
systemctl is-enabled nginxWill nginx start by itself at the next boot?
systemctl list-units --type=service --state=runningEvery service running right now.
systemctl list-units --state=failedEvery unit that has failed: a good first look after a bad boot.
systemctl list-unit-files --type=service --state=enabledEvery service set to start at boot.
Common mistakes
The action comes first, then the unit: here systemctl reads 'nginx' as an unknown command.