/usr/share/systemtap/examples/lwtools
NameSizeModeActions
accept2close-nd.814240644editdlrm
accept2close-nd.meta5970644editdlrm
accept2close-nd.stp17980755editdlrm
accept2close-nd.txt33850644editdlrm
biolatency-nd.816710644editdlrm
biolatency-nd.meta6220644editdlrm
biolatency-nd.stp20710755editdlrm
biolatency-nd_example.txt73620644editdlrm
bitesize-nd.811570644editdlrm
bitesize-nd.meta4910644editdlrm
bitesize-nd.stp15430755editdlrm
bitesize-nd_example.txt34260644editdlrm
execsnoop-nd.812350644editdlrm
execsnoop-nd.meta5700644editdlrm
execsnoop-nd.stp12830755editdlrm
execsnoop-nd_example.txt25850644editdlrm
fslatency-nd.819300644editdlrm
fslatency-nd.meta6600644editdlrm
fslatency-nd.stp39820755editdlrm
fslatency-nd_example.txt133840644editdlrm
fsslower-nd.817530644editdlrm
fsslower-nd.meta6230644editdlrm
fsslower-nd.stp37150755editdlrm
fsslower-nd_example.txt19380644editdlrm
killsnoop-nd.811310644editdlrm
killsnoop-nd.meta3840644editdlrm
killsnoop-nd.stp12810755editdlrm
killsnoop-nd_example.txt19080644editdlrm
opensnoop-nd.812680644editdlrm
opensnoop-nd.meta3570644editdlrm
opensnoop-nd.stp10260755editdlrm
opensnoop-nd_example.txt11240644editdlrm
README1070644editdlrm
rwtime-nd.811460644editdlrm
rwtime-nd.meta4120644editdlrm
rwtime-nd.stp15990755editdlrm
rwtime-nd_example.txt41850644editdlrm
syscallbypid-nd.810890644editdlrm
syscallbypid-nd.meta4040644editdlrm
syscallbypid-nd.stp11000755editdlrm
syscallbypid-nd_example.txt93220644editdlrm
Edit: /usr/share/systemtap/examples/lwtools/accept2close-nd.txt (3385B)
Examples of accept2close-nd.stp, the Linux SystemTap version. This shows accepted socket lifespans, by measuring the time from syscall accept() to close() on the same file descriptor. Sessions are printed as they occur, and a histogram summary is printed at the end. For example: # ./accept2close-nd.stp TIME PID COMM FD DURATION Sat Jan 31 05:31:14 2015 29042 node 11 1 ms Sat Jan 31 05:31:15 2015 29042 node 11 1 ms Sat Jan 31 05:31:15 2015 29042 node 11 1 ms Sat Jan 31 05:31:15 2015 29042 node 11 1 ms Sat Jan 31 05:31:15 2015 29042 node 11 1 ms Sat Jan 31 05:31:15 2015 29042 node 11 1 ms Sat Jan 31 05:31:15 2015 29042 node 11 1 ms Sat Jan 31 05:31:15 2015 29042 node 11 1 ms Sat Jan 31 05:31:15 2015 29042 node 11 1 ms Sat Jan 31 05:31:15 2015 29042 node 11 1 ms Sat Jan 31 05:31:15 2015 29042 node 11 1 ms Sat Jan 31 05:31:15 2015 29042 node 11 1 ms Sat Jan 31 05:31:15 2015 29042 node 11 2 ms Sat Jan 31 05:31:15 2015 29042 node 11 3 ms Sat Jan 31 05:31:15 2015 29042 node 11 2 ms Sat Jan 31 05:31:15 2015 29042 node 11 1 ms Sat Jan 31 05:31:15 2015 29042 node 11 1 ms Sat Jan 31 05:31:15 2015 29042 node 11 1 ms Sat Jan 31 05:31:15 2015 29042 node 11 1 ms [...] Duration (ns): value |-------------------------------------------------- count 131072 | 0 262144 | 0 524288 | 1 1048576 |@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ 138 2097152 |@@ 6 4194304 | 1 8388608 | 0 16777216 | 0 Most of these sessions were between 1 and 2 milliseconds in lifespan. The socket lifespan is expected to represent the time taken by a server to respond to a request. This time may include cycles on-CPU, and cycles off-CPU blocked on another resource. Note that HTTP keep-alive sessions may have long durations which process multiple requests. accept2close-nd.stp accepts an optional argument: a minimum lifespan threshold in milliseconds. For example, socket sessions that are 5 milliseconds and longer: # ./accept2close-nd.stp 5 Only tracing events slower than 5 ms. TIME PID COMM FD DURATION Sat Jan 31 05:36:23 2015 5236 node 11 5 ms Sat Jan 31 05:37:39 2015 5236 node 11 5 ms Sat Jan 31 05:37:50 2015 5236 node 11 9 ms Sat Jan 31 05:38:09 2015 5236 node 11 7 ms ^C Duration (ns): value |-------------------------------------------------- count 1048576 | 0 2097152 | 0 4194304 |@@@ 3 8388608 |@ 1 16777216 | 0 33554432 | 0