TiloBox
Back to directory
bpftrace project preview

bpftrace

High-level tracing language for Linux enhanced Berkeley Packet Filter (eBPF).

LicenseApache-2.0
GitHub stars9.5k
Last commit1 weeks ago
Tags6 topics
Kernel DiagnosticsDtrace LinuxKprobes UprobesEbpf TracingDevopsCpp Bpftrace
Overview

Why consider bpftrace?

bpftrace is a high-level tracing language and runtime for Linux eBPF written in C++ by Alastair Robertson. Inspired by DTrace and awk, bpftrace allows engineers to write concise one-liner scripts that inspect kernel probes (kprobes), tracepoints, and userspace probes (uprobes) without overhead.

Guided learning

Learn bpftrace by building

Practical setup notes, real use cases, and copy-ready examples in one focused guide.

1 min read 2 sections
In this guide2 sections

Overview of bpftrace

bpftrace executes expressive dynamic kernel probes on live production Linux servers.

Quickstart

bash
1# Trace open() syscalls by process
2sudo bpftrace -e 'tracepoint:syscalls:sys_enter_openat { printf("%s %s\n", comm, str(args->filename)); }'

bpftrace is licensed under the Apache License Version 2.0.

Related tools

More options with a similar category or technology profile.

bpftrace FAQs

bpftrace is listed as a Developer Tools tool on TiloBox. Review the overview, features, and official documentation on this page to decide whether it solves your specific workflow.

Start with the project's GitHub repository and official website for supported installation and deployment instructions. Test the setup with representative data or a small project before rolling it out more widely.

bpftrace is listed under the Apache-2.0 license. Read the complete license text and the project's notices before using, modifying, or distributing the software.

Production readiness depends on your requirements. Review maintenance activity, security practices, documentation, backup and upgrade procedures, and compatibility with your stack; then validate it in a non-production environment.

bpftrace is listed as an alternative to DTrace. Compare the core workflow, deployment model, integrations, and licensing against your must-have requirements before switching.