Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Hi,
Thank you for this project.
I would want to use
argdist
but instead of getting the PID I need the process name. The reason being I have short lived processes, and I want to inspect the sockets created by the processes if they are non-blocking. To make it easier to identify the process I want the tool to print the process name, supporting something likeargdist -c -C 't:syscalls:sys_enter_accept4():int,char*,int:args->fd,$COMM,args->flags&00004000'
. I managed to make some code changes in this PR but I am facing an issue with the output, see belowAlthough the COMM is successfully extracted, it results in what should be the same count being separate. I am assuming this is due to the pointer to the COMM being saved in the BPF_HASH map. I would appreciate pointers to resolving this.
Thanks,