Collecting Data
eBPF and BCC provide powerful tools for capturing tracepoint events from the Linux kernel and drivers. Tracepoints are predefined event sources in the kernel, such as function calls or system call entries, and BCC simplifies their collection and analysis through high-level utilities. This section demonstrates how to use BCC to gather and process tracepoint data effectively.
Using BCC Tools to Capture Tracepoint Data¶
BCC includes the trace and tracepoint commands for interacting with kernel tracepoints. These tools abstract the complexity of eBPF program compilation and event handling, allowing users to focus on filtering and analysis.
Basic Tracepoint Collection¶
To capture tracepoint events, use the trace command with the -p option to specify a process ID (PID) or --all to trace all processes:
# Trace all processes for sys_enter_open events
sudo trace -p all -e sys:sys_enter_open
# Trace a specific PID (e.g., PID 1234) for sched_switch events
sudo trace -p 1234 -e sched:sched_switch
The -e flag filters events by name (e.g., sys:sys_enter_open). For a list of available tracepoints, use:
Tracing Driver-Specific Events¶
For kernel modules or drivers, use the tracepoint command to target specific events. For example, to trace DMA operations in a network driver:
This command captures events from the net_dev_xmit tracepoint, which is triggered when a network device transmits data.
Filtering and Analyzing Tracepoint Data¶
BCC provides utilities like stat, histogram, and perf to process collected tracepoint data. These tools aggregate events, calculate statistics, and visualize trends.
Aggregating Event Counts¶
Use stat to count occurrences of specific events over time:
# Count sys_open calls per second
sudo trace -p all -e sys:sys_open | sudo stat -c "%t %s %c" sys_open
This outputs timestamps and counts of sys_open events, helping identify patterns or anomalies.
Generating Histograms¶
The histogram tool creates visualizations of event distributions. For example, to analyze latency of sys_open calls:
This generates a histogram showing the distribution of open() call latencies.
Exporting Data for External Analysis¶
Use perf to export tracepoint data for further analysis with tools like perf report or flamegraph:
Key Takeaways¶
- Use
traceandtracepointcommands to capture kernel and driver events without writing eBPF programs manually. - Filter events with
-eand analyze data usingstat,histogram, orperffor insights into system behavior. - BCC abstracts eBPF complexity, enabling rapid deployment of tracepoint-based monitoring and troubleshooting workflows.