SlideShare a Scribd company logo
1 of 18
Alejandro E. Brito Monedero
@ae_bm
http://us.cdn1.123rf.com/168nwm/chagall/chagall0903/chagall090300002/4464959-a-pot-of-gold.jpg
http://vancouvertoollibrary.com/wp-content/uploads/2016/02/tools_cropped.jpg
http://www.tac-focus.com/sites/default/files/images/HowDoYouSeeTheWorld.jpg
https://www.sciencenews.org/sites/default/files/2016/01/main/articles/012216_ag_entangledhistory_free.jpg
strace
It cannot trace all processes
UX ….
Context switches everywhere
multiprocess ….
Wireshark
Only network
High traffic networks
How to relate a network capture with a process
that is not currently running?
http://www.ababolfashion.com/sites/default/files/imagecache/product_full/i_small_crop.jpg
eBPF
http://cdn.static-economist.com/sites/default/files/images/print-edition/20130406_LDP001_0.jpg
HN
http://www.fatosdesconhecidos.com.br/wp-content/uploads/2015/05/1105.jpg
Sysdig
strace & wireshark had a child
containers containers containers
save captures
chisels (lua scripts)
syscall level only
Needs to compile a kernel module
http://www.brendangregg.com/Perf/linux_observability_tools.png
Sysdig
Containers
docker run -i -t --name sysdig --privileged -v 
/var/run/docker.sock:/host/var/run/docker.sock 
-v /dev:/host/dev -v /proc:/host/proc:ro 
-v /boot:/host/boot:ro 
-v /lib/modules:/host/lib/modules:ro 
-v /usr:/host/usr:ro sysdig/sysdig
http://www.sysdig.org/install/
Examples
Store all the open syscalls in the system
sysdig -w capture.scap evt.type=open
Top 10 slowest syscalls
sysdig -c bottlenecks "evt.latency > 0"
Examples
What does cron writes or read from its FDs
sysdig -c echo_fds disable_color proc.name=cron
What files where opened in the system
sysdig -r capture.scap -p "%proc.name" | sort | uniq
Examples
Create a more filtered captured file
sysdig -r capture.scap -w comm_capt.scap
“proc.name = command”
P0rn
sysdig -c spectrogram
sysdig -c subsecoffset
csysdig
More info about sysdig
Internet
http://www.sysdig.org/wiki/
https://sysdig.com/blog/linux-
troubleshooting-cheatsheet/
View all filters available
sysdig -l
More info about sysdig
List chisels
sysdig -cl
View supported events
sysdig -L
Chisel info
sysdig -i <chisel>
Happy ending
http://adorablekittens.com/wp-content/uploads/2015/10/cats.jpg

More Related Content

What's hot

Owasp hyd 28_dec2013_opensamm
Owasp hyd 28_dec2013_opensammOwasp hyd 28_dec2013_opensamm
Owasp hyd 28_dec2013_opensammM S Sripati
 
Utensilios de cocina
Utensilios de cocinaUtensilios de cocina
Utensilios de cocinapilarandres
 
Mborell newsilent week6
Mborell newsilent week6Mborell newsilent week6
Mborell newsilent week6mborell
 
Personal Persona Project - Zachary Pago
Personal Persona Project - Zachary PagoPersonal Persona Project - Zachary Pago
Personal Persona Project - Zachary PagoZachary-Pago
 
Final PPP Slide Show
Final PPP Slide ShowFinal PPP Slide Show
Final PPP Slide ShowJessV82
 
Comportamientos digitales!
Comportamientos digitales! Comportamientos digitales!
Comportamientos digitales! NathaliaFonseca
 
Anatomy of a web page
Anatomy of a web pageAnatomy of a web page
Anatomy of a web pagedharvey100
 
On Screen: The Multi-Screen Marketing Lessons of Star Trek
On Screen: The Multi-Screen Marketing Lessons of Star TrekOn Screen: The Multi-Screen Marketing Lessons of Star Trek
On Screen: The Multi-Screen Marketing Lessons of Star TrekAnjuan Simmons
 
Hum186 final3 (6)
Hum186 final3 (6)Hum186 final3 (6)
Hum186 final3 (6)Rachel Teo
 
Network topology hardware
Network topology hardwareNetwork topology hardware
Network topology hardwareJames1280
 
Links for key nots
Links for key notsLinks for key nots
Links for key notsErappaTuppad
 
Wind Pad 100w NUI interface PK
Wind Pad 100w NUI interface PKWind Pad 100w NUI interface PK
Wind Pad 100w NUI interface PKIM450ROCKS
 
Macro photography
Macro photographyMacro photography
Macro photographykarlareyezz
 

What's hot (20)

Owasp hyd 28_dec2013_opensamm
Owasp hyd 28_dec2013_opensammOwasp hyd 28_dec2013_opensamm
Owasp hyd 28_dec2013_opensamm
 
Utensilios de cocina
Utensilios de cocinaUtensilios de cocina
Utensilios de cocina
 
Desarrollo sostenible
Desarrollo sostenibleDesarrollo sostenible
Desarrollo sostenible
 
Mborell newsilent week6
Mborell newsilent week6Mborell newsilent week6
Mborell newsilent week6
 
Personal Persona Project - Zachary Pago
Personal Persona Project - Zachary PagoPersonal Persona Project - Zachary Pago
Personal Persona Project - Zachary Pago
 
Final PPP Slide Show
Final PPP Slide ShowFinal PPP Slide Show
Final PPP Slide Show
 
Comportamientos digitales!
Comportamientos digitales! Comportamientos digitales!
Comportamientos digitales!
 
French Power Point
French Power PointFrench Power Point
French Power Point
 
Anatomy of a web page
Anatomy of a web pageAnatomy of a web page
Anatomy of a web page
 
Robot moodboard
Robot moodboardRobot moodboard
Robot moodboard
 
On Screen: The Multi-Screen Marketing Lessons of Star Trek
On Screen: The Multi-Screen Marketing Lessons of Star TrekOn Screen: The Multi-Screen Marketing Lessons of Star Trek
On Screen: The Multi-Screen Marketing Lessons of Star Trek
 
Submiter + backlink
Submiter + backlinkSubmiter + backlink
Submiter + backlink
 
Hum186 final3 (6)
Hum186 final3 (6)Hum186 final3 (6)
Hum186 final3 (6)
 
Network topology hardware
Network topology hardwareNetwork topology hardware
Network topology hardware
 
Links for key nots
Links for key notsLinks for key nots
Links for key nots
 
Wind Pad 100w NUI interface PK
Wind Pad 100w NUI interface PKWind Pad 100w NUI interface PK
Wind Pad 100w NUI interface PK
 
Business model generation
Business model generationBusiness model generation
Business model generation
 
References 111
References 111References 111
References 111
 
Lean & T.O.C
Lean & T.O.CLean & T.O.C
Lean & T.O.C
 
Macro photography
Macro photographyMacro photography
Macro photography
 

Similar to Sysdig SRECon 16 Europe

Diseases of pre modern europe
Diseases of pre modern europeDiseases of pre modern europe
Diseases of pre modern europeKathy Turnbull
 
Digital Fluency, starting with digital annotation
Digital Fluency, starting with digital annotationDigital Fluency, starting with digital annotation
Digital Fluency, starting with digital annotationAnne-Mart Olsen
 
Las posibilidades de la web 2
Las posibilidades de la web 2Las posibilidades de la web 2
Las posibilidades de la web 2glopamonag
 
Las posibilidades de la web 2
Las posibilidades de la web 2Las posibilidades de la web 2
Las posibilidades de la web 2glopamonag
 
[Azure Council Experts (ACE) 第35回定例会] Microsoft Azureアップデート情報 (2019/04/19-201...
[Azure Council Experts (ACE) 第35回定例会] Microsoft Azureアップデート情報 (2019/04/19-201...[Azure Council Experts (ACE) 第35回定例会] Microsoft Azureアップデート情報 (2019/04/19-201...
[Azure Council Experts (ACE) 第35回定例会] Microsoft Azureアップデート情報 (2019/04/19-201...Naoki (Neo) SATO
 
Thaddeus marshall Personal Persona Project
Thaddeus marshall Personal Persona ProjectThaddeus marshall Personal Persona Project
Thaddeus marshall Personal Persona ProjectTerrill Marshall
 
Integrating Information Technology with Sports (by Chris and Sean)
Integrating Information Technology with Sports (by Chris and Sean)Integrating Information Technology with Sports (by Chris and Sean)
Integrating Information Technology with Sports (by Chris and Sean)ChrisEluva
 
Tactics to Kickstart Your Journey Toward DevOps
Tactics to Kickstart Your Journey Toward DevOpsTactics to Kickstart Your Journey Toward DevOps
Tactics to Kickstart Your Journey Toward DevOpsJeff Gallimore
 
Tactics to Kickstart Your Journey Toward DevOps
Tactics to Kickstart Your Journey Toward DevOpsTactics to Kickstart Your Journey Toward DevOps
Tactics to Kickstart Your Journey Toward DevOpsExcella
 
Escalabilidade com Akka
Escalabilidade com AkkaEscalabilidade com Akka
Escalabilidade com AkkaDiego Pacheco
 
Stefan Judis "Did we(b development) lose the right direction?"
Stefan Judis "Did we(b development) lose the right direction?"Stefan Judis "Did we(b development) lose the right direction?"
Stefan Judis "Did we(b development) lose the right direction?"Fwdays
 
المجموعة التشاركية الاولى
المجموعة التشاركية الاولىالمجموعة التشاركية الاولى
المجموعة التشاركية الاولىOla7
 
Traditional symbols in literature
Traditional symbols in literatureTraditional symbols in literature
Traditional symbols in literaturekcurranlitlover
 

Similar to Sysdig SRECon 16 Europe (20)

Diseases of pre modern europe
Diseases of pre modern europeDiseases of pre modern europe
Diseases of pre modern europe
 
Slide show koby
Slide show kobySlide show koby
Slide show koby
 
Pagines de les fotos
Pagines de les fotosPagines de les fotos
Pagines de les fotos
 
Digital Fluency, starting with digital annotation
Digital Fluency, starting with digital annotationDigital Fluency, starting with digital annotation
Digital Fluency, starting with digital annotation
 
Diachi
DiachiDiachi
Diachi
 
Las posibilidades de la web 2
Las posibilidades de la web 2Las posibilidades de la web 2
Las posibilidades de la web 2
 
Las posibilidades de la web 2
Las posibilidades de la web 2Las posibilidades de la web 2
Las posibilidades de la web 2
 
[Azure Council Experts (ACE) 第35回定例会] Microsoft Azureアップデート情報 (2019/04/19-201...
[Azure Council Experts (ACE) 第35回定例会] Microsoft Azureアップデート情報 (2019/04/19-201...[Azure Council Experts (ACE) 第35回定例会] Microsoft Azureアップデート情報 (2019/04/19-201...
[Azure Council Experts (ACE) 第35回定例会] Microsoft Azureアップデート情報 (2019/04/19-201...
 
Thaddeus marshall Personal Persona Project
Thaddeus marshall Personal Persona ProjectThaddeus marshall Personal Persona Project
Thaddeus marshall Personal Persona Project
 
Integrating Information Technology with Sports (by Chris and Sean)
Integrating Information Technology with Sports (by Chris and Sean)Integrating Information Technology with Sports (by Chris and Sean)
Integrating Information Technology with Sports (by Chris and Sean)
 
Contaminacion
ContaminacionContaminacion
Contaminacion
 
Tactics to Kickstart Your Journey Toward DevOps
Tactics to Kickstart Your Journey Toward DevOpsTactics to Kickstart Your Journey Toward DevOps
Tactics to Kickstart Your Journey Toward DevOps
 
Tactics to Kickstart Your Journey Toward DevOps
Tactics to Kickstart Your Journey Toward DevOpsTactics to Kickstart Your Journey Toward DevOps
Tactics to Kickstart Your Journey Toward DevOps
 
Comportamientos digitales
Comportamientos digitalesComportamientos digitales
Comportamientos digitales
 
Comportamientos digitales
Comportamientos digitalesComportamientos digitales
Comportamientos digitales
 
Escalabilidade com Akka
Escalabilidade com AkkaEscalabilidade com Akka
Escalabilidade com Akka
 
Stefan Judis "Did we(b development) lose the right direction?"
Stefan Judis "Did we(b development) lose the right direction?"Stefan Judis "Did we(b development) lose the right direction?"
Stefan Judis "Did we(b development) lose the right direction?"
 
المجموعة التشاركية الاولى
المجموعة التشاركية الاولىالمجموعة التشاركية الاولى
المجموعة التشاركية الاولى
 
Cite sources
Cite sourcesCite sources
Cite sources
 
Traditional symbols in literature
Traditional symbols in literatureTraditional symbols in literature
Traditional symbols in literature
 

More from Alejandro E Brito Monedero (14)

Mad scalability (perfomance debugging)
Mad scalability (perfomance debugging)Mad scalability (perfomance debugging)
Mad scalability (perfomance debugging)
 
Tres historias
Tres historiasTres historias
Tres historias
 
AMQP vs GRAPHITE
AMQP vs GRAPHITEAMQP vs GRAPHITE
AMQP vs GRAPHITE
 
Sysdig
SysdigSysdig
Sysdig
 
Funcional para trollear
Funcional para trollearFuncional para trollear
Funcional para trollear
 
Top Bug
Top BugTop Bug
Top Bug
 
Fabric más allá de lo básico
Fabric más allá de lo básicoFabric más allá de lo básico
Fabric más allá de lo básico
 
Experiencias con PostgreSQL en AWS
Experiencias con PostgreSQL en AWSExperiencias con PostgreSQL en AWS
Experiencias con PostgreSQL en AWS
 
Fabric Fast & Furious edition
Fabric Fast & Furious editionFabric Fast & Furious edition
Fabric Fast & Furious edition
 
Así que pusiste MongoDB. Dime ¿cómo lo administras?
Así que pusiste MongoDB. Dime ¿cómo lo administras?Así que pusiste MongoDB. Dime ¿cómo lo administras?
Así que pusiste MongoDB. Dime ¿cómo lo administras?
 
AWS Baby steps circa 2008
AWS Baby steps circa 2008AWS Baby steps circa 2008
AWS Baby steps circa 2008
 
Using Logstash, elasticsearch & kibana
Using Logstash, elasticsearch & kibanaUsing Logstash, elasticsearch & kibana
Using Logstash, elasticsearch & kibana
 
Wireshark tips
Wireshark tipsWireshark tips
Wireshark tips
 
Mi experiencia con Amazon AWS EC2 y S3
Mi experiencia con Amazon AWS EC2 y S3Mi experiencia con Amazon AWS EC2 y S3
Mi experiencia con Amazon AWS EC2 y S3
 

Recently uploaded

Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxLoriGlavin3
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024Stephanie Beckett
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024Lonnie McRorey
 
Search Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfSearch Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfRankYa
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 3652toLead Limited
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationSlibray Presentation
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxNavinnSomaal
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLScyllaDB
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfAlex Barbosa Coqueiro
 
The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsPixlogix Infotech
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024Lorenzo Miniero
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfAddepto
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr BaganFwdays
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Enterprise Knowledge
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.Curtis Poe
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clashcharlottematthew16
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionDilum Bandara
 
Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsMiki Katsuragi
 

Recently uploaded (20)

Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024
 
Search Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfSearch Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdf
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck Presentation
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptx
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQL
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdf
 
The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and Cons
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdf
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clash
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An Introduction
 
Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering Tips
 

Sysdig SRECon 16 Europe