/
usr
/
share
/
doc
/
bpftrace
/
examples
/
/usr/share/doc/bpftrace/examples
mkdir
upload
Name
Size
Mode
Actions
bashreadline_example.txt
722
0644
edit
dl
rm
biolatency_example.txt
1790
0644
edit
dl
rm
biosnoop_example.txt
2056
0644
edit
dl
rm
biostacks_example.txt
1914
0644
edit
dl
rm
bitesize_example.txt
3003
0644
edit
dl
rm
capable_example.txt
2659
0644
edit
dl
rm
cpuwalk_example.txt
4919
0644
edit
dl
rm
dcsnoop_example.txt
4612
0644
edit
dl
rm
execsnoop_example.txt
1535
0644
edit
dl
rm
gethostlatency_example.txt
923
0644
edit
dl
rm
killsnoop_example.txt
846
0644
edit
dl
rm
loads_example.txt
864
0644
edit
dl
rm
mdflush_example.txt
1866
0644
edit
dl
rm
naptime_example.txt
844
0644
edit
dl
rm
oomkill_example.txt
1668
0644
edit
dl
rm
opensnoop_example.txt
2528
0644
edit
dl
rm
pidpersec_example.txt
1504
0644
edit
dl
rm
runqlat_example.txt
8632
0644
edit
dl
rm
runqlen_example.txt
980
0644
edit
dl
rm
setuids_example.txt
2441
0644
edit
dl
rm
ssllatency_example.txt
4510
0644
edit
dl
rm
sslsnoop_example.txt
1916
0644
edit
dl
rm
statsnoop_example.txt
2738
0644
edit
dl
rm
swapin_example.txt
549
0644
edit
dl
rm
syncsnoop_example.txt
541
0644
edit
dl
rm
syscount_example.txt
1144
0644
edit
dl
rm
tcpaccept_example.txt
1350
0644
edit
dl
rm
tcpconnect_example.txt
1085
0644
edit
dl
rm
tcpdrop_example.txt
1256
0644
edit
dl
rm
tcplife_example.txt
1597
0644
edit
dl
rm
tcpretrans_example.txt
1153
0644
edit
dl
rm
tcpsynbl_example.txt
940
0644
edit
dl
rm
threadsnoop_example.txt
1182
0644
edit
dl
rm
undump_example.txt
680
0644
edit
dl
rm
vfscount_example.txt
1199
0644
edit
dl
rm
vfsstat_example.txt
929
0644
edit
dl
rm
writeback_example.txt
1962
0644
edit
dl
rm
xfsdist_example.txt
3419
0644
edit
dl
rm
Edit:
/usr/share/doc/bpftrace/examples/execsnoop_example.txt
(1535B)
Demonstrations of execsnoop, the Linux BPF/bpftrace version. Tracing all new process execution (via exec()): # ./execsnoop.bt Attaching 3 probes... TIME PID PPID ARGS 08:57:52.430193 3187374 1971701 ls --color --color=auto -lh execsnoop.bt execsnoop.bt.0 execsnoop.bt.1 08:57:52.441868 3187378 3187375 man ls 08:57:52.473565 3187384 3187378 preconv -e UTF-8 08:57:52.473620 3187384 3187378 preconv -e UTF-8 08:57:52.473658 3187384 3187378 preconv -e UTF-8 08:57:52.473839 3187385 3187378 tbl 08:57:52.473897 3187385 3187378 tbl 08:57:52.473944 3187385 3187378 tbl 08:57:52.474055 3187386 3187378 nroff -mandoc -Tutf8 08:57:52.474107 3187386 3187378 nroff -mandoc -Tutf8 08:57:52.474145 3187386 3187378 nroff -mandoc -Tutf8 08:57:52.474684 3187388 3187378 less 08:57:52.474739 3187388 3187378 less 08:57:52.474780 3187388 3187378 less 08:57:52.475502 3187389 3187386 groff -Tutf8 -mtty-char -mandoc 08:57:52.476717 3187390 3187389 troff -mtty-char -mandoc -Tutf8 08:57:52.476811 3187391 3187389 grotty The output begins by showing an "ls" command, and then the process execution to serve "man ls". The same exec arguments appear multiple times: in this case they are failing as the $PATH variable is walked, until one finally succeeds. This tool can be used to discover unwanted short-lived processes that may be causing performance issues such as latency perturbations. There is another version of this tool in bcc: https://github.com/iovisor/bcc The bcc version provides more fields and command line options.
Save
cmd:
run