Documentation is sparse in details. Is this built on top of kprobes[1]? If so a comparison with perf, systemtap, et al is probably more appropriate. Do you support utrace/uprobes or similar for userland work?
Is data selection/manipulation/summarization available on the kernal side? At high rates extracting enough/iptimal data has caught me with other linux probe based tools.
I like the ring buffer and scap concept. Very nice compared to the full dump or summarized stats other tools focus on.
No, we don't use kprobes at this point, all of our collection is done through tracepoints. Take a look at https://github.com/draios/sysdig/blob/master/driver/main.c for details. They tend to be very efficient, which is a very important requirement because of our "capture all" approach.
And no urace/uprobes support yet. We're considering it as a feature for the future.
Is data selection/manipulation/summarization available on the kernal side? At high rates extracting enough/iptimal data has caught me with other linux probe based tools.
I like the ring buffer and scap concept. Very nice compared to the full dump or summarized stats other tools focus on.
[1] https://www.kernel.org/doc/Documentation/kprobes.txt