4 ms·
Summoning the spirit (and more importantly the expertise) of brendangregg here. From the home page sysdig "capture[s] system state and activity", but by levera
by heybrendan 10y ago
Summoning the spirit (and more importantly the expertise) of brendangregg here.
From the home page sysdig "capture[s] system state and activity", but by leveraging specifically what?
From https://sysdig.com/blog/sysdig-vs-dtrace-vs-strace-a-technical-discussion/ https://sysdig.com/blog/sysdig-vs-dtrace-vs-strace-a-technic...:
"First, events are captured in the kernel by a small driver, called sysdig-probe, which leverages a kernel facility called tracepoints."
That makes it sound like it's quite similar to the ftrace kernel tracer by instrumenting the various event tracepoints (/sys/kernel/debug/tracing/available_events) conveniently strewn throughout the kernel source--is this indeed the case?
Alternatively, is sysdig doing something differently? {k,u}probes? Sampling similar to, perhaps say, perf's capabilities?
The Linux tracing/profiling landscape is murky enough (littered with tools like SystemTap, LTTng, and so forth) and I'd like to know where this tool fits into an analysis work-flow--and more importantly, what's it's using (at a low-level) to gather data.
I'd appreciate any and all clarification.
Cheers.
- luca3m 10y agosysdig uses "tracepoints", a feature of the Linux Kernel documented here: https://www.kernel.org/doc/Documentation/trace/tracepoints.txt https://www.kernel.org/doc/Documentation/trace/tracepoints.t... The tracing capabilities are then tuned for monitoring and troubleshooting. So keeping the overhead as low as possible and making it usable on production environments.