bpftrace

High-level tracing language for Linux eBPF. More information: https://github.com/iovisor/bpftrace.

bpftrace -V

sudo bpftrace -l

sudo bpftrace -e 'tracepoint:raw_syscalls:sys_enter { @[comm] = count(); }'

sudo bpftrace path/to/file

sudo bpftrace -e 'tracepoint:raw_syscalls:sys_enter /pid == 123/ { @[comm] = count(); }'

sudo bpftrace -d -e 'one_line_program'