1 .TH newproc.d 1m "$Date:: 2007-08-05 #$" "USER COMMANDS"
3 newproc.d \- snoop new processes. Uses DTrace.
7 newproc.d is a DTrace OneLiner to snoop new processes as they are run.
8 The argument listing is printed.
10 This is useful to identify short lived processes that are usually
11 difficult to spot using traditional tools.
13 Docs/oneliners.txt and Docs/Examples/oneliners_examples.txt
14 in the DTraceToolkit contain this as a oneliner that can be cut-n-paste
17 Since this uses DTrace, only the root user or users with the
18 dtrace_kernel privilege can run this command.
22 stable - needs the proc provider.
25 This prints new processes until Ctrl\-C is hit.
32 The CPU that recieved the event
35 A DTrace probe ID for the event
38 The DTrace probe name for the event
41 These contains the argument listing for the new process
44 See the DTraceToolkit for further documentation under the
45 Docs directory. The DTraceToolkit docs may include full worked
46 examples with verbose descriptions explaining the output.
48 newproc.d will run forever until Ctrl\-C is hit.
53 execsnoop(1M), dtrace(1M), truss(1)