strace -e trace= — How Do You Filter Syscalls?
strace e trace filtering keeps only the syscalls you care about instead of dumping everything. With strace(1)’s -e trace= / --trace=, you pick names, regexes, or % classes so logs stay short and readable. This post covers three axes only: filter syntax · network/file-only · performance cost. It is not a full strace intro (install, -p attach, reading raw lines). No pricing, affiliates, or invented benchmarks.
Grounded in the strace(1) man page sections on -e expr and -e trace=.
What is the filter syntax?
One-line answer: -e expr uses [qualifier=][!]value[,value].... If you omit the qualifier, it defaults to trace. So -e open equals -e trace=open, and --trace= is the same idea.
Common shapes:
| Form | Meaning |
|---|---|
-e trace=open | Only open |
-e trace=open,close,read,write | Listed calls only |
-e trace=!open | Everything except open |
-e trace=all / none | All / none (default is all) |
-e trace=/^open/ | Names matching a POSIX ERE |
# default qualifier=trace
strace -e open cat /dev/null
strace -e trace=open,close cat /dev/null
strace --trace=open,close cat /dev/null
# negation: shells may treat ! as history — quote or escape
strace -e 'trace=!open' cat /dev/null
strace -e trace=\!open cat /dev/null
Extra syntax from the man page:
?value: suppress errors when nothing matches.value@64/@32/@x32: limit to that personality.- Watching a subset makes it hard to infer full user/kernel behavior for untraced calls—the man page warns about this.
To decide what to keep, run -c / --summary-only first, then tighten trace= from that histogram.
How do you see only network or file calls?
One-line answer: Use %file for path-taking calls and %net (or %network) for networking. Bare file / network without % is deprecated in the man page—prefer the % forms.
# which paths does the process touch?
strace -e trace=%file ls /tmp
# sockets / connect / … only
strace -e trace=%net curl -sI https://example.com
# both
strace -e trace=%file,%net your-app
Useful % classes (excerpt):
| Class | Role |
|---|---|
%file | Syscalls that take a file name (open/stat/unlink family, …) |
%net / %network | Network-related syscalls |
%process | Lifecycle (create, exec, exit) |
%desc | File-descriptor related |
%signal | Signal related |
%memory | Memory-mapping related |
%file exists so you do not hand-list open,stat,... and accidentally omit variants like newfstatat—the man page says so explicitly.
To narrow further by path, use -P path / --trace-path= (repeatable). To limit by FD set, use -e trace-fds= (also drops calls that never touch FDs).
strace -P /etc/passwd -e trace=%file cat /etc/passwd
What is the performance cost?
One-line answer: A traced process runs slower than an untraced one. Shrinking printed output with trace= is not the same as stopping only on selected syscalls via --seccomp-bpf.
From the BUGS section:
- Tracing slows the target.
- Impact can be mitigated with
--seccomp-bpf. --seccomp-bpfmatters together with-f/--follow-forks; it is not compatible with-pattach and some other options.- If seccomp-bpf setup fails, strace falls back to stopping on every syscall as usual.
Practical reading:
trace=%filealone — less log I/O and noise; without seccomp-bpf, broad ptrace stops may still apply.- Hot paths / tight timeouts — keep the smallest
syscall_set, and for children consider-f --seccomp-bpf. - Counts only — prefer
-cover a huge stream. - Production — short reproduce windows beat always-on attach.
strace -f --seccomp-bpf -e trace=%net -o net.log your-server
strace -c -e trace=%file your-app
Frequently asked questions
Are -e open and -e trace=open different?
No. The default qualifier is trace.
Why does ! break in my shell?
History expansion. Quote the expression or escape \!.
How is this different from a full strace intro?
Intros cover “what / start / attach.” This piece is filter syntax, %file/%net, and cost only.
Does filtering always make things faster?
Less output helps readability; ptrace cost can remain. To reduce stops to the traced set, check the man page conditions for --seccomp-bpf.
What should you remember?
Pick the set with strace -e trace=, prefer %file / %net for file and network slices, and treat slowdown as inherent to tracing—optionally mitigate with --seccomp-bpf (plus -f). Source: strace(1). No affiliates.
Where are the official sources?
- strace(1) — Linux man-pages —
-e expr,-e trace=,%classes,--seccomp-bpf, BUGS - strace.io — project home