strace -e trace= — How Do You Filter Syscalls?

strace e trace filtering keeps only the syscalls you care about instead of dumping everything. With strace(1)’s -e trace= / --trace=, you pick names, regexes, or % classes so logs stay short and readable. This post covers three axes only: filter syntax · network/file-only · performance cost. It is not a full strace intro (install, -p attach, reading raw lines). No pricing, affiliates, or invented benchmarks.

Grounded in the strace(1) man page sections on -e expr and -e trace=.

What is the filter syntax?

One-line answer: -e expr uses [qualifier=][!]value[,value].... If you omit the qualifier, it defaults to trace. So -e open equals -e trace=open, and --trace= is the same idea.

Common shapes:

FormMeaning
-e trace=openOnly open
-e trace=open,close,read,writeListed calls only
-e trace=!openEverything except open
-e trace=all / noneAll / none (default is all)
-e trace=/^open/Names matching a POSIX ERE
# default qualifier=trace
strace -e open cat /dev/null
strace -e trace=open,close cat /dev/null
strace --trace=open,close cat /dev/null

# negation: shells may treat ! as history — quote or escape
strace -e 'trace=!open' cat /dev/null
strace -e trace=\!open cat /dev/null

Extra syntax from the man page:

  • ?value: suppress errors when nothing matches.
  • value@64 / @32 / @x32: limit to that personality.
  • Watching a subset makes it hard to infer full user/kernel behavior for untraced calls—the man page warns about this.

To decide what to keep, run -c / --summary-only first, then tighten trace= from that histogram.

How do you see only network or file calls?

One-line answer: Use %file for path-taking calls and %net (or %network) for networking. Bare file / network without % is deprecated in the man page—prefer the % forms.

# which paths does the process touch?
strace -e trace=%file ls /tmp

# sockets / connect / … only
strace -e trace=%net curl -sI https://example.com

# both
strace -e trace=%file,%net your-app

Useful % classes (excerpt):

ClassRole
%fileSyscalls that take a file name (open/stat/unlink family, …)
%net / %networkNetwork-related syscalls
%processLifecycle (create, exec, exit)
%descFile-descriptor related
%signalSignal related
%memoryMemory-mapping related

%file exists so you do not hand-list open,stat,... and accidentally omit variants like newfstatat—the man page says so explicitly.

To narrow further by path, use -P path / --trace-path= (repeatable). To limit by FD set, use -e trace-fds= (also drops calls that never touch FDs).

strace -P /etc/passwd -e trace=%file cat /etc/passwd

What is the performance cost?

One-line answer: A traced process runs slower than an untraced one. Shrinking printed output with trace= is not the same as stopping only on selected syscalls via --seccomp-bpf.

From the BUGS section:

  • Tracing slows the target.
  • Impact can be mitigated with --seccomp-bpf.
  • --seccomp-bpf matters together with -f / --follow-forks; it is not compatible with -p attach and some other options.
  • If seccomp-bpf setup fails, strace falls back to stopping on every syscall as usual.

Practical reading:

  1. trace=%file alone — less log I/O and noise; without seccomp-bpf, broad ptrace stops may still apply.
  2. Hot paths / tight timeouts — keep the smallest syscall_set, and for children consider -f --seccomp-bpf.
  3. Counts only — prefer -c over a huge stream.
  4. Production — short reproduce windows beat always-on attach.
strace -f --seccomp-bpf -e trace=%net -o net.log your-server
strace -c -e trace=%file your-app

Frequently asked questions

Are -e open and -e trace=open different?
No. The default qualifier is trace.

Why does ! break in my shell?
History expansion. Quote the expression or escape \!.

How is this different from a full strace intro?
Intros cover “what / start / attach.” This piece is filter syntax, %file/%net, and cost only.

Does filtering always make things faster?
Less output helps readability; ptrace cost can remain. To reduce stops to the traced set, check the man page conditions for --seccomp-bpf.

What should you remember?

Pick the set with strace -e trace=, prefer %file / %net for file and network slices, and treat slowdown as inherent to tracing—optionally mitigate with --seccomp-bpf (plus -f). Source: strace(1). No affiliates.

Where are the official sources?