4 ms·
Thanks. To answer the question "what it does and how", sysdig captures system calls and other system level events using a linux kernel facility called tracepoi
by degio 13y ago
Thanks.
To answer the question "what it does and how", sysdig captures system calls and other system level events using a linux kernel facility called tracepoints, which means much less overhead than strace.
It then "packetizes" this information, so that you can save it into trace files and filter it, a bit like you would do with tcpdump. This makes it very flexible to explore what processes are doing.
We also pack it with a set of scripts that make it easier to extract useful information and do troubleshooting.
- peterwwillis 13y agoSee, that is a really good description that would be useful in a README. Right away I know what it is, what it does and whether I should use it.
- degio 13y agoAs you suggested, we've updated the README with the content above.