| Server IP : 216.250.13.251 / Your IP : 216.73.216.164 Web Server : nginx/1.24.0 System : Linux gunay 6.8.0-134-generic #134-Ubuntu SMP PREEMPT_DYNAMIC Fri Jun 26 18:43:11 UTC 2026 x86_64 User : root ( 0) PHP Version : 7.4.33 Disable Function : pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_get_handler,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,pcntl_async_signals,pcntl_unshare, MySQL : OFF | cURL : ON | WGET : ON | Perl : ON | Python : OFF | Sudo : ON | Pkexec : OFF Directory : /usr/share/doc/bpfcc-tools/examples/doc/ |
Upload File : |
Demonstrations of filegone, the Linux eBPF/bcc version.
filegone traces why file gone, either been deleted or renamed
For example:
# ./filegone
18:30:56 22905 vim DELETE .fstab.swpx
18:30:56 22905 vim DELETE .fstab.swp
18:31:00 22905 vim DELETE .viminfo
18:31:00 22905 vim RENAME .viminfo.tmp > .viminfo
18:31:00 22905 vim DELETE .fstab.swp
USAGE message:
usage: filegone.py [-h] [-p PID]
Trace why file gone (deleted or renamed)
optional arguments:
-h, --help show this help message and exit
-p PID, --pid PID trace this PID only
examples:
./filegone # trace all file gone events
./filegone -p 181 # only trace PID 181