How To Add eBPF Observability To Your Product
Brendan Gregg
JULY 2, 2021
E.g., to see process execution with timestamps using execsnoop(8): # execsnoop-bpfcc -T. If you want to run these tools 24x7, study overheads to understand the cost first. Low frequency events such as process execution should be negligible to capture. execsnoop New processes (via exec(2)) table. Then try running a tool.
Let's personalize your content