1 .TH creatbyproc.d 1m "$Date:: 2007-08-05 #$" "USER COMMANDS"
3 creatbyproc.d \- snoop creat()s by process name. Uses DTrace.
7 creatbyproc.d is a DTrace OneLiner to print file creations as it
8 occurs, including the name of the process calling the open.
10 This matches file creates from the creat() system call; not all
11 file creation occurs in this way, sometimes it is through open()
12 with a O_CREAT flag, this script will not monitor that activity.
14 Docs/oneliners.txt and Docs/Examples/oneliners_examples.txt
15 in the DTraceToolkit contain this as a oneliner that can be cut-n-paste
18 Since this uses DTrace, only the root user or users with the
19 dtrace_kernel privilege can run this command.
23 stable - needs the syscall provider.
26 This prints process names and new pathnames until Ctrl\-C is hit.
33 The CPU that recieved the event
36 A DTrace probe ID for the event
39 The DTrace probe name for the event
42 The first is the name of the process, the second is the file pathname.
45 See the DTraceToolkit for further documentation under the
46 Docs directory. The DTraceToolkit docs may include full worked
47 examples with verbose descriptions explaining the output.
49 creatbyproc.d will run forever until Ctrl\-C is hit.