creatbyproc.d(1m) USER COMMANDS creatbyproc.d(1m)NAMEcreatbyproc.d - snoop creat()s by process name. Uses DTrace.SYNOPSIScreatbyproc.dDESCRIPTIONcreatbyproc.d is a DTrace OneLiner to print file creations as it occurs, including the name of the process calling the open. This matches file creates from the creat() system call; not all file creation occurs in this way, sometimes it is through open() with a O_CREAT flag, this script will not monitor that activity. Docs/oneliners.txt and Docs/Examples/oneliners_examples.txt in the DTraceToolkit contain this as a oneliner that can be cut-n-paste to run. Since this uses DTrace, only users with root privileges can run this command.EXAMPLESThis prints process names and new pathnames until Ctrl-C is hit. # creatbyproc.dFIELDSCPU The CPU that recieved the event ID A DTrace probe ID for the event FUNCTION:NAME The DTrace probe name for the event remaining fields The first is the name of the process, the second is the file pathname.DOCUMENTATIONSee the DTraceToolkit for further documentation under the Docs directory. The DTraceToolkit docs may include full worked examples with ver- bose descriptions explaining the output.EXITcreatbyproc.d will run forever until Ctrl-C is hit.AUTHORBrendan Gregg [Sydney, Australia]SEE ALSOdtrace(1M) version 1.00 Jun 11, 2005 creatbyproc.d(1m)