vltrace: syscall tracer using eBPF
This is the top-level README.md of vltrace.
vltrace is a syscall tracing tool which utilizes eBPF - an efficient tracing feature of the Linux kernel.
Please see the file LICENSE for information on how this tool is licensed.
- kernel v4.7 or later (to attach eBPF to tracepoints)
- kernel headers installed:
- 'kernel-devel' package on RHEL, Fedora and CentOS or
- 'linux-headers' package on Debian and Ubuntu
- libbcc v0.4.0
- CAP_SYS_ADMIN capability (required by the bpf() syscall)
- mounted debugfs and tracefs
For more information about this tool contact:
- Lukasz Dorau (lukasz.dorau at intel.com)
or create an issue here.