newproc.d(1m) USER COMMANDS newproc.d(1m)NAMEnewproc.d - snoop new processes. Uses DTrace.
SYNOPSISnewproc.dDESCRIPTIONnewproc.d is a DTrace OneLiner to snoop new processes as they are run.
The argument listing is printed.
This is useful to identify short lived processes that are usually dif‐
ficult to spot using traditional tools.
Docs/oneliners.txt and Docs/Examples/oneliners_examples.txt in the
DTraceToolkit contain this as a oneliner that can be cut-n-paste to
run.
Since this uses DTrace, only users with root privileges can run this
command.
EXAMPLES
This prints new processes until Ctrl-C is hit.
# newproc.dFIELDS
CPU The CPU that recieved the event
ID A DTrace probe ID for the event
FUNCTION:NAME
The DTrace probe name for the event
remaining fields
These contains the argument listing for the new process
DOCUMENTATION
See the DTraceToolkit for further documentation under the Docs direc‐
tory. The DTraceToolkit docs may include full worked examples with ver‐
bose descriptions explaining the output.
EXITnewproc.d will run forever until Ctrl-C is hit.
AUTHOR
Brendan Gregg [Sydney, Australia]
SEE ALSOexecsnoop(1M), dtrace(1M), truss(1)version 1.00 May 15, 2005 newproc.d(1m)