1 .TH rwsnoop 1m "$Date:: 2007-08-05 #$" "USER COMMANDS"
3 rwsnoop \- snoop read/write events. Uses DTrace.
6 [\-jPtvZ] [\-n name] [\-p PID]
8 This is measuring reads and writes at the application level. This
9 matches the syscalls read, write, pread and pwrite.
11 Since this uses DTrace, only the root user or users with the
12 dtrace_kernel privilege can run this command.
16 stable - needs the syscall provider.
23 print parent process ID
51 Monitor processes named "bash",
80 command name for the process
83 direction, Read or Write
86 total bytes during sample
89 filename, if file based.
90 Reads and writes that are not file based, for example with sockets, will
91 print "<unknown>" as the filename.
94 See the DTraceToolkit for further documentation under the
95 Docs directory. The DTraceToolkit docs may include full worked
96 examples with verbose descriptions explaining the output.
98 rwsnoop will run forever until Ctrl\-C is hit.
103 rwtop(1M), dtrace(1M)