/
usr
/
share
/
doc
/
bpfcc-tools
/
examples
/
doc
/
/usr/share/doc/bpfcc-tools/examples/doc
mkdir
upload
Name
Size
Mode
Actions
lib/
-
0755
rm
argdist_example.txt
23029
0644
edit
dl
rm
bashreadline_example.txt
882
0644
edit
dl
rm
bindsnoop_example.txt
4530
0644
edit
dl
rm
biolatency_example.txt
24021
0644
edit
dl
rm
biolatpcts_example.txt
3040
0644
edit
dl
rm
biopattern_example.txt
1406
0644
edit
dl
rm
biosnoop_example.txt
3549
0644
edit
dl
rm
biotop_example.txt
9326
0644
edit
dl
rm
bitesize_example.txt
5100
0644
edit
dl
rm
bpflist_example.txt
2179
0644
edit
dl
rm
btrfsdist_example.txt
9545
0644
edit
dl
rm
btrfsslower_example.txt
6812
0644
edit
dl
rm
cachestat_example.txt
4012
0644
edit
dl
rm
cachetop_example.txt
3918
0644
edit
dl
rm
capable_example.txt
6655
0644
edit
dl
rm
cobjnew_example.txt
3044
0644
edit
dl
rm
compactsnoop_example.txt
10160
0644
edit
dl
rm
cpudist_example.txt
16876
0644
edit
dl
rm
cpuunclaimed_example.txt
15568
0644
edit
dl
rm
criticalstat_example.txt
4926
0644
edit
dl
rm
cthreads_example.txt
2132
0644
edit
dl
rm
dbslower_example.txt
3981
0644
edit
dl
rm
dbstat_example.txt
6656
0644
edit
dl
rm
dcsnoop_example.txt
4371
0644
edit
dl
rm
dcstat_example.txt
3343
0644
edit
dl
rm
deadlock_example.txt
16643
0644
edit
dl
rm
dirtop_example.txt
5097
0644
edit
dl
rm
drsnoop_example.txt
5120
0644
edit
dl
rm
execsnoop_example.txt
6795
0644
edit
dl
rm
exitsnoop_example.txt
6373
0644
edit
dl
rm
ext4dist_example.txt
8991
0644
edit
dl
rm
ext4slower_example.txt
11335
0644
edit
dl
rm
filegone_example.txt
743
0644
edit
dl
rm
filelife_example.txt
2092
0644
edit
dl
rm
fileslower_example.txt
5711
0644
edit
dl
rm
filetop_example.txt
6968
0644
edit
dl
rm
funccount_example.txt
13605
0644
edit
dl
rm
funcinterval_example.txt
15646
0644
edit
dl
rm
funclatency_example.txt
21485
0644
edit
dl
rm
funcslower_example.txt
6786
0644
edit
dl
rm
gethostlatency_example.txt
1317
0644
edit
dl
rm
hardirqs_example.txt
37936
0644
edit
dl
rm
inject_example.txt
6832
0644
edit
dl
rm
javacalls_example.txt
4000
0644
edit
dl
rm
javaflow_example.txt
6017
0644
edit
dl
rm
javagc_example.txt
3867
0644
edit
dl
rm
javaobjnew_example.txt
3044
0644
edit
dl
rm
javastat_example.txt
3052
0644
edit
dl
rm
javathreads_example.txt
2132
0644
edit
dl
rm
killsnoop_example.txt
1339
0644
edit
dl
rm
klockstat_example.txt
8536
0644
edit
dl
rm
kvmexit_example.txt
11909
0644
edit
dl
rm
llcstat_example.txt
3315
0644
edit
dl
rm
mdflush_example.txt
1780
0644
edit
dl
rm
memleak_example.txt
10263
0644
edit
dl
rm
mountsnoop_example.txt
1481
0644
edit
dl
rm
mysqld_qslower_example.txt
2351
0644
edit
dl
rm
netqtop_example.txt
12497
0644
edit
dl
rm
nfsdist_example.txt
8508
0644
edit
dl
rm
nfsslower_example.txt
7867
0644
edit
dl
rm
nodegc_example.txt
3867
0644
edit
dl
rm
nodestat_example.txt
3052
0644
edit
dl
rm
offcputime_example.txt
19662
0644
edit
dl
rm
offwaketime_example.txt
38258
0644
edit
dl
rm
oomkill_example.txt
1925
0644
edit
dl
rm
opensnoop_example.txt
10573
0644
edit
dl
rm
perlcalls_example.txt
4000
0644
edit
dl
rm
perlflow_example.txt
6017
0644
edit
dl
rm
perlstat_example.txt
3052
0644
edit
dl
rm
phpcalls_example.txt
4000
0644
edit
dl
rm
phpflow_example.txt
6017
0644
edit
dl
rm
phpstat_example.txt
3052
0644
edit
dl
rm
pidpersec_example.txt
677
0644
edit
dl
rm
ppchcalls_example.txt
7097
0644
edit
dl
rm
profile_example.txt
31826
0644
edit
dl
rm
pythoncalls_example.txt
4000
0644
edit
dl
rm
pythonflow_example.txt
6017
0644
edit
dl
rm
pythongc_example.txt
3867
0644
edit
dl
rm
pythonstat_example.txt
3052
0644
edit
dl
rm
rdmaucma_example.txt
1983
0644
edit
dl
rm
readahead_example.txt
3248
0644
edit
dl
rm
reset-trace_example.txt
9365
0644
edit
dl
rm
rubycalls_example.txt
4000
0644
edit
dl
rm
rubyflow_example.txt
6017
0644
edit
dl
rm
rubygc_example.txt
3867
0644
edit
dl
rm
rubyobjnew_example.txt
3044
0644
edit
dl
rm
rubystat_example.txt
3052
0644
edit
dl
rm
runqlat_example.txt
32051
0644
edit
dl
rm
runqlen_example.txt
12136
0644
edit
dl
rm
runqslower_example.txt
2184
0644
edit
dl
rm
shmsnoop_example.txt
2798
0644
edit
dl
rm
slabratetop_example.txt
5347
0644
edit
dl
rm
sofdsnoop_example.txt
3211
0644
edit
dl
rm
softirqs_example.txt
11286
0644
edit
dl
rm
solisten_example.txt
2355
0644
edit
dl
rm
sslsniff_example.txt
6902
0644
edit
dl
rm
stackcount_example.txt
21965
0644
edit
dl
rm
statsnoop_example.txt
3091
0644
edit
dl
rm
swapin.txt
2632
0644
edit
dl
rm
swapin_example.txt
1421
0644
edit
dl
rm
syncsnoop_example.txt
387
0644
edit
dl
rm
syscount_example.txt
6419
0644
edit
dl
rm
tclcalls_example.txt
4000
0644
edit
dl
rm
tclflow_example.txt
6017
0644
edit
dl
rm
tclobjnew_example.txt
3044
0644
edit
dl
rm
tclstat_example.txt
3052
0644
edit
dl
rm
tcpaccept_example.txt
2822
0644
edit
dl
rm
tcpcong_example.txt
34106
0644
edit
dl
rm
tcpconnect_example.txt
6420
0644
edit
dl
rm
tcpconnlat_example.txt
2616
0644
edit
dl
rm
tcpdrop_example.txt
2001
0644
edit
dl
rm
tcplife_example.txt
6995
0644
edit
dl
rm
tcpretrans_example.txt
3938
0644
edit
dl
rm
tcprtt_example.txt
10070
0644
edit
dl
rm
tcpstates_example.txt
2908
0644
edit
dl
rm
tcpsubnet_example.txt
5503
0644
edit
dl
rm
tcpsynbl_example.txt
1179
0644
edit
dl
rm
tcptop_example.txt
5890
0644
edit
dl
rm
tcptracer_example.txt
2029
0644
edit
dl
rm
threadsnoop_example.txt
1094
0644
edit
dl
rm
tplist_example.txt
4507
0644
edit
dl
rm
trace_example.txt
22136
0644
edit
dl
rm
ttysnoop_example.txt
3315
0644
edit
dl
rm
vfscount_example.txt
2221
0644
edit
dl
rm
vfsstat_example.txt
1696
0644
edit
dl
rm
virtiostat_example.txt
2678
0644
edit
dl
rm
wakeuptime_example.txt
34048
0644
edit
dl
rm
xfsdist_example.txt
6928
0644
edit
dl
rm
xfsslower_example.txt
7080
0644
edit
dl
rm
zfsdist_example.txt
9753
0644
edit
dl
rm
zfsslower_example.txt
7551
0644
edit
dl
rm
Edit:
/usr/share/doc/bpfcc-tools/examples/doc/tcplife_example.txt
(6995B)
Demonstrations of tcplife, the Linux BPF/bcc version. tcplife summarizes TCP sessions that open and close while tracing. For example: # ./tcplife PID COMM LADDR LPORT RADDR RPORT TX_KB RX_KB MS 22597 recordProg 127.0.0.1 46644 127.0.0.1 28527 0 0 0.23 3277 redis-serv 127.0.0.1 28527 127.0.0.1 46644 0 0 0.28 22598 curl 100.66.3.172 61620 52.205.89.26 80 0 1 91.79 22604 curl 100.66.3.172 44400 52.204.43.121 80 0 1 121.38 22624 recordProg 127.0.0.1 46648 127.0.0.1 28527 0 0 0.22 3277 redis-serv 127.0.0.1 28527 127.0.0.1 46648 0 0 0.27 22647 recordProg 127.0.0.1 46650 127.0.0.1 28527 0 0 0.21 3277 redis-serv 127.0.0.1 28527 127.0.0.1 46650 0 0 0.26 [...] This caught a program, "recordProg" making a few short-lived TCP connections to "redis-serv", lasting about 0.25 milliseconds each connection. A couple of "curl" sessions were also traced, connecting to port 80, and lasting 91 and 121 milliseconds. This tool is useful for workload characterisation and flow accounting: identifying what connections are happening, with the bytes transferred. Process names are truncated to 10 characters. By using the wide option, -w, the column width becomes 16 characters. The IP address columns are also wider to fit IPv6 addresses: # ./tcplife -w PID COMM IP LADDR LPORT RADDR RPORT TX_KB RX_KB MS 26315 recordProgramSt 4 127.0.0.1 44188 127.0.0.1 28527 0 0 0.21 3277 redis-server 4 127.0.0.1 28527 127.0.0.1 44188 0 0 0.26 26320 ssh 6 fe80::8a3:9dff:fed5:6b19 22440 fe80::8a3:9dff:fed5:6b19 22 1 1 457.52 26321 sshd 6 fe80::8a3:9dff:fed5:6b19 22 fe80::8a3:9dff:fed5:6b19 22440 1 1 458.69 26341 recordProgramSt 4 127.0.0.1 44192 127.0.0.1 28527 0 0 0.27 3277 redis-server 4 127.0.0.1 28527 127.0.0.1 44192 0 0 0.32 In this example, I uploaded a 10 Mbyte file to the server, and then downloaded it again, using scp: # ./tcplife PID COMM LADDR LPORT RADDR RPORT TX_KB RX_KB MS 7715 recordProg 127.0.0.1 50894 127.0.0.1 28527 0 0 0.25 3277 redis-serv 127.0.0.1 28527 127.0.0.1 50894 0 0 0.30 7619 sshd 100.66.3.172 22 100.127.64.230 63033 5 10255 3066.79 7770 recordProg 127.0.0.1 50896 127.0.0.1 28527 0 0 0.20 3277 redis-serv 127.0.0.1 28527 127.0.0.1 50896 0 0 0.24 7793 recordProg 127.0.0.1 50898 127.0.0.1 28527 0 0 0.23 3277 redis-serv 127.0.0.1 28527 127.0.0.1 50898 0 0 0.27 7847 recordProg 127.0.0.1 50900 127.0.0.1 28527 0 0 0.24 3277 redis-serv 127.0.0.1 28527 127.0.0.1 50900 0 0 0.29 7870 recordProg 127.0.0.1 50902 127.0.0.1 28527 0 0 0.29 3277 redis-serv 127.0.0.1 28527 127.0.0.1 50902 0 0 0.30 7798 sshd 100.66.3.172 22 100.127.64.230 64925 10265 6 2176.15 [...] You can see the 10 Mbytes received by sshd, and then later transmitted. Looks like receive was slower (3.07 seconds) than transmit (2.18 seconds). Timestamps can be added with -t: # ./tcplife -t TIME(s) PID COMM LADDR LPORT RADDR RPORT TX_KB RX_KB MS 0.000000 5973 recordProg 127.0.0.1 47986 127.0.0.1 28527 0 0 0.25 0.000059 3277 redis-serv 127.0.0.1 28527 127.0.0.1 47986 0 0 0.29 1.022454 5996 recordProg 127.0.0.1 47988 127.0.0.1 28527 0 0 0.23 1.022513 3277 redis-serv 127.0.0.1 28527 127.0.0.1 47988 0 0 0.27 2.044868 6019 recordProg 127.0.0.1 47990 127.0.0.1 28527 0 0 0.24 2.044924 3277 redis-serv 127.0.0.1 28527 127.0.0.1 47990 0 0 0.28 3.069136 6042 recordProg 127.0.0.1 47992 127.0.0.1 28527 0 0 0.22 3.069204 3277 redis-serv 127.0.0.1 28527 127.0.0.1 47992 0 0 0.28 This shows that the recordProg process was connecting once per second. There's also a -T for HH:MM:SS formatted times. There's a comma separated values mode, -s. Here it is with both -t and -T timestamps: # ./tcplife -stT TIME,TIME(s),PID,COMM,IP,LADDR,LPORT,RADDR,RPORT,TX_KB,RX_KB,MS 23:39:38,0.000000,7335,recordProgramSt,4,127.0.0.1,48098,127.0.0.1,28527,0,0,0.26 23:39:38,0.000064,3277,redis-server,4,127.0.0.1,28527,127.0.0.1,48098,0,0,0.32 23:39:39,1.025078,7358,recordProgramSt,4,127.0.0.1,48100,127.0.0.1,28527,0,0,0.25 23:39:39,1.025141,3277,redis-server,4,127.0.0.1,28527,127.0.0.1,48100,0,0,0.30 23:39:41,2.040949,7381,recordProgramSt,4,127.0.0.1,48102,127.0.0.1,28527,0,0,0.24 23:39:41,2.041011,3277,redis-server,4,127.0.0.1,28527,127.0.0.1,48102,0,0,0.29 23:39:42,3.067848,7404,recordProgramSt,4,127.0.0.1,48104,127.0.0.1,28527,0,0,0.30 23:39:42,3.067914,3277,redis-server,4,127.0.0.1,28527,127.0.0.1,48104,0,0,0.35 [...] There are options for filtering on local and remote ports. Here is filtering on local ports 22 and 80: # ./tcplife.py -L 22,80 PID COMM LADDR LPORT RADDR RPORT TX_KB RX_KB MS 8301 sshd 100.66.3.172 22 100.127.64.230 58671 3 3 1448.52 [...] USAGE: # ./tcplife.py -h usage: tcplife.py [-h] [-T] [-t] [-w] [-s] [-p PID] [-L LOCALPORT] [-D REMOTEPORT] [-4 | -6] Trace the lifespan of TCP sessions and summarize optional arguments: -h, --help show this help message and exit -T, --time include time column on output (HH:MM:SS) -t, --timestamp include timestamp on output (seconds) -w, --wide wide column output (fits IPv6 addresses) -s, --csv comma separated values output -p PID, --pid PID trace this PID only -L LOCALPORT, --localport LOCALPORT comma-separated list of local ports to trace. -D REMOTEPORT, --remoteport REMOTEPORT comma-separated list of remote ports to trace. -4, --ipv4 trace IPv4 family only -6, --ipv6 trace IPv6 family only examples: ./tcplife # trace all TCP connect()s ./tcplife -t # include time column (HH:MM:SS) ./tcplife -w # wider columns (fit IPv6) ./tcplife -stT # csv output, with times & timestamps ./tcplife -p 181 # only trace PID 181 ./tcplife -L 80 # only trace local port 80 ./tcplife -L 80,81 # only trace local ports 80 and 81 ./tcplife -D 80 # only trace remote port 80 ./tcplife -4 # only trace IPv4 family ./tcplife -6 # only trace IPv6 family
Save
cmd:
run