I know that with ps
I can see the list or tree of the current processes running in the system. But what I want to achieve is to "follow" the new processes that are created when using the computer.
As analogy, when you use tail -f
to follow the new contents appended to a file or to any input, then I want to keep a follow list of the process that are currently being created.
Is this even posible?
Best Answer
If kprobes are enabled in the kernel you can use
execsnoop
from perf-tools:In first terminal:
In another terminal: