Sysdig vs DTrace vs Strace: a technical discussion
draios.com
draios.com
Is data selection/manipulation/summarization available on the kernal side? At high rates extracting enough/iptimal data has caught me with other linux probe based tools.
I like the ring buffer and scap concept. Very nice compared to the full dump or summarized stats other tools focus on.
The sysdig command line style is promising, and it's exciting to see innovation in this space, but what's there right now is still give and take. Try writing a DTrace aggregation and a sysdig chisel side by side, to see what I mean. In many common cases sysdig is much more laborious to use right now.
More functionality can be added to sysdig (aggregations -- or chisel functions, thread local variables, tracepoints, kprobes, uprobes, PMCs, register inspection, kernel stacks, user stacks, user stack helpers, kernel filters and aggregations), allowing it to catch up to what DTrace can do, and solve the problems it can solve.
But I think comparing sysdig to DTrace is either wrong or premature. If sysdig isn't going to do those features I mentioned, then it's a different type of tool (nothing wrong with that), but it is misleading and unfair on itself to compare it to DTrace. If it is going to do those features -- and it just hasn't yet -- then why compare it to DTrace now? sysdig will be giving people a poor first impression, and again, it's unfair on itself.
For anyone wanting to compare, who isn't that familiar with perf, here's _some_ of the things perf can do: http://www.brendangregg.com/perf.html .