/usr/share/systemtap/examples/lwtools
NameSizeModeActions
accept2close-nd.814240644editdlrm
accept2close-nd.meta5970644editdlrm
accept2close-nd.stp17980755editdlrm
accept2close-nd.txt33850644editdlrm
biolatency-nd.816710644editdlrm
biolatency-nd.meta6220644editdlrm
biolatency-nd.stp20710755editdlrm
biolatency-nd_example.txt73620644editdlrm
bitesize-nd.811570644editdlrm
bitesize-nd.meta4910644editdlrm
bitesize-nd.stp15430755editdlrm
bitesize-nd_example.txt34260644editdlrm
execsnoop-nd.812350644editdlrm
execsnoop-nd.meta5700644editdlrm
execsnoop-nd.stp12830755editdlrm
execsnoop-nd_example.txt25850644editdlrm
fslatency-nd.819300644editdlrm
fslatency-nd.meta6600644editdlrm
fslatency-nd.stp39820755editdlrm
fslatency-nd_example.txt133840644editdlrm
fsslower-nd.817530644editdlrm
fsslower-nd.meta6230644editdlrm
fsslower-nd.stp37150755editdlrm
fsslower-nd_example.txt19380644editdlrm
killsnoop-nd.811310644editdlrm
killsnoop-nd.meta3840644editdlrm
killsnoop-nd.stp12810755editdlrm
killsnoop-nd_example.txt19080644editdlrm
opensnoop-nd.812680644editdlrm
opensnoop-nd.meta3570644editdlrm
opensnoop-nd.stp10260755editdlrm
opensnoop-nd_example.txt11240644editdlrm
README1070644editdlrm
rwtime-nd.811460644editdlrm
rwtime-nd.meta4120644editdlrm
rwtime-nd.stp15990755editdlrm
rwtime-nd_example.txt41850644editdlrm
syscallbypid-nd.810890644editdlrm
syscallbypid-nd.meta4040644editdlrm
syscallbypid-nd.stp11000755editdlrm
syscallbypid-nd_example.txt93220644editdlrm
Edit: /usr/share/systemtap/examples/lwtools/accept2close-nd.stp (1798B)
#!/usr/bin/stap /* * accept2close-nd.stp Show socket duration: accept()->close(). * * USAGE: ./accept2close.stp [min_ms] * * NOTE: This will miss sockets that are opened by one process, and then closed * by another (eg, sshd). * * A minimum latency threshold, in milliseconds, can be provided as an optional * argument. Without this, all events are shown. * * Copyright (C) 2015 Brendan Gregg. * * This program is free software; you can redistribute it and/or modify * it under the terms of the GNU General Public License as published by * the Free Software Foundation; either version 2 of the License, or * (at your option) any later version. * * This program is distributed in the hope that it will be useful, * but WITHOUT ANY WARRANTY; without even the implied warranty of * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the * GNU General Public License for more details. * * 20-Jun-2014 Brendan Gregg Created this. */ global duration, ts, min_ns; probe begin { # process arguments if (argv_1 != "") { min_ns = strtol(argv_1, 10) * 1000000; printf("Only tracing events slower than %s ms.\n", argv_1); } else { min_ns = 0; } printf("%-24s %-6s %-14s %-4s %s\n", "TIME", "PID", "COMM", "FD", "DURATION"); } probe nd_syscall.accept.return, nd_syscall.accept4.return { ts[tid(), retval] = gettimeofday_ns(); } probe nd_syscall.close { last = ts[tid(), int_arg(1)]; if (last) { delta = gettimeofday_ns() - last; if (delta >= min_ns) { printf("%-24s %-6d %-14s %-4d %d ms\n", ctime(gettimeofday_s()), pid(), execname(), int_arg(1), delta / 1000000); duration <<< delta; } delete ts[tid(), int_arg(1)]; } } probe end { printf("\nDuration (ns):\n"); if (@count(duration)) { print(@hist_log(duration)); } }