/usr/share/systemtap/examples/lwtools
NameSizeModeActions
accept2close-nd.814240644editdlrm
accept2close-nd.meta5970644editdlrm
accept2close-nd.stp17980755editdlrm
accept2close-nd.txt33850644editdlrm
biolatency-nd.816710644editdlrm
biolatency-nd.meta6220644editdlrm
biolatency-nd.stp20710755editdlrm
biolatency-nd_example.txt73620644editdlrm
bitesize-nd.811570644editdlrm
bitesize-nd.meta4910644editdlrm
bitesize-nd.stp15430755editdlrm
bitesize-nd_example.txt34260644editdlrm
execsnoop-nd.812350644editdlrm
execsnoop-nd.meta5700644editdlrm
execsnoop-nd.stp12830755editdlrm
execsnoop-nd_example.txt25850644editdlrm
fslatency-nd.819300644editdlrm
fslatency-nd.meta6600644editdlrm
fslatency-nd.stp39820755editdlrm
fslatency-nd_example.txt133840644editdlrm
fsslower-nd.817530644editdlrm
fsslower-nd.meta6230644editdlrm
fsslower-nd.stp37150755editdlrm
fsslower-nd_example.txt19380644editdlrm
killsnoop-nd.811310644editdlrm
killsnoop-nd.meta3840644editdlrm
killsnoop-nd.stp12810755editdlrm
killsnoop-nd_example.txt19080644editdlrm
opensnoop-nd.812680644editdlrm
opensnoop-nd.meta3570644editdlrm
opensnoop-nd.stp10260755editdlrm
opensnoop-nd_example.txt11240644editdlrm
README1070644editdlrm
rwtime-nd.811460644editdlrm
rwtime-nd.meta4120644editdlrm
rwtime-nd.stp15990755editdlrm
rwtime-nd_example.txt41850644editdlrm
syscallbypid-nd.810890644editdlrm
syscallbypid-nd.meta4040644editdlrm
syscallbypid-nd.stp11000755editdlrm
syscallbypid-nd_example.txt93220644editdlrm
Edit: /usr/share/systemtap/examples/lwtools/bitesize-nd_example.txt (3426B)
Examples of bitesize-nd.stp, the Linux SystemTap version. This shows size distributions for requested block I/O, by process name: # ./bitesize-nd.stp Tracing block I/O... Hit Ctrl-C to end. ^C I/O size (bytes): process name: flush-202:1 value |-------------------------------------------------- count 1024 | 0 2048 | 0 4096 |@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ 33 8192 |@@@@@@@@@@@@@@@@ 16 16384 |@@@@@@@@@ 9 32768 |@@@@ 4 65536 |@@@ 3 131072 | 0 262144 | 0 process name: kjournald value |-------------------------------------------------- count 1024 | 0 2048 | 0 4096 |@ 4 8192 | 2 16384 | 2 32768 |@ 7 65536 |@ 5 131072 |@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ 182 262144 | 0 524288 | 0 process name: randread.pl value |-------------------------------------------------- count 1024 | 0 2048 | 0 4096 | 4 8192 |@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ 1859 16384 | 0 32768 | 5 65536 | 18 131072 | 0 262144 | 0 process name: tar value |-------------------------------------------------- count 1024 | 0 2048 | 0 4096 |@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ 1645 8192 |@@@@@@@@@@@@@@@@@@@@@@@@@ 836 16384 |@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ 1394 32768 |@@@@@@@@@@@@@@@@ 532 65536 |@@@@@ 180 131072 |@@@@@@ 219 262144 | 0 524288 | 0 tar(1) was archiving a directory of varying sized files, and writing an output file, which creates the distribution seen above. The randread.pl program was performing 8 Kbyte random reads. Note that there were a few larger I/O: some custom SystemTap can be used to explain this. Eg, show kernel stack traces for I/O larger than 32 Kbytes. I'd guess it was file system metadata. The aim of this tool is to help characterize the disk I/O workload.