bpftrace (DTrace 2.0) for Linux 2018
Brendan Gregg
OCTOBER 8, 2018
Syscall count by program bpftrace -e 'tracepoint:raw_syscalls:sys_enter { @[comm] = count(); }'. bcc is powerful but laborious to program. Internally, bpftrace uses a lex/yacc parser to convert programs to AST, then llvm IR actions, then BPF. Here's key differences as of August 2018: Type DTrace bpftrace. eBPF does more.
Let's personalize your content