Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

sysdig logdata incomplete, when I specify the log information and output format #1596

Open
codingjin opened this issue Feb 24, 2020 · 2 comments

Comments

@codingjin
Copy link

According to the manual, I define my output format, and use the sysdig command in this way:
sysdig -p "%evt.num %evt.time name=%proc.name pid=%proc.pid <exe %proc.exe /exe> cwd=%proc.cwd dir=%evt.dir syscall=%syscall.type <args %evt.args/args> fd=%fd.num fd_type=%fd.type fd_name=%fd.name" -w log01

But I find the log is incomplete, like I cannot find the clone, syscall events, as I expected.
And I can find more information, like the expected clone event, in the default way, like just typing sysdig.

sysdig version 0.26.4
Operating System: Ubuntu 18.04.4 LTS

@ChangZhu1997
Copy link

Same problem happens to me. Strange thing is i used to collect some information, but now even though i did not change sysdig script, the log is incomplete.

@github-actions
Copy link

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@github-actions github-actions bot added the stale label Feb 22, 2023
@github-actions github-actions bot closed this as not planned Won't fix, can't repro, duplicate, stale Mar 2, 2023
@therealbobo therealbobo reopened this Mar 9, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants