Display Filter Reference: Sysdig System Call

Protocol field name: sysdig

Versions: 2.0.0 to 3.6.8

Back to Display Filter Reference

Field name Description Type Versions
sysdig.cpu_id CPU ID Unsigned integer (2 bytes) 2.0.0 to 3.6.8
sysdig.event_len Event length Unsigned integer (4 bytes) 2.0.0 to 3.6.8
sysdig.event_type Event type Unsigned integer (2 bytes) 2.0.0 to 3.6.8
sysdig.nparams Number of parameters Unsigned integer (4 bytes) 3.2.13 to 3.2.18, 3.4.5 to 3.6.8
sysdig.param.accept.fd fd Signed integer (8 bytes) 2.0.0 to 3.0.14
sysdig.param.accept.flags flags Unsigned integer (4 bytes) 2.0.0 to 3.6.8
sysdig.param.accept.queuelen queuelen Unsigned integer (4 bytes) 2.0.0 to 3.6.8
sysdig.param.accept.queuemax queuemax Unsigned integer (4 bytes) 2.0.0 to 3.6.8
sysdig.param.accept.queuepct Accept queue per connection Unsigned integer (1 byte) 2.0.0 to 3.6.8
sysdig.param.accept.tuple tuple Byte sequence 2.0.0 to 3.6.8
sysdig.param.access.mode mode Byte sequence 3.2.0 to 3.6.0
sysdig.param.bpf.cmd cmd Signed integer (8 bytes) 3.2.0 to 3.6.8
sysdig.param.bpf.res_or_fd res_or_fd Byte sequence 3.2.0 to 3.6.8
sysdig.param.chmod.filename filename Character string 3.6.1 to 3.6.8
sysdig.param.container.id id Character string 2.0.0 to 3.0.14
sysdig.param.container.image image Character string 2.0.0 to 3.6.8
sysdig.param.container.json json Character string 3.2.0 to 3.6.8
sysdig.param.container.type type Unsigned integer (4 bytes) 2.0.0 to 3.6.8
sysdig.param.cpu_hotplug.action action Unsigned integer (4 bytes) 2.0.0 to 3.6.8
sysdig.param.cpu_hotplug.cpu cpu Unsigned integer (4 bytes) 2.0.0 to 3.6.8
sysdig.param.drop.ratio ratio Unsigned integer (4 bytes) 2.0.0 to 3.6.8
sysdig.param.epoll_wait.maxevents maxevents Byte sequence 2.0.0 to 3.6.8
sysdig.param.eventfd.initval initval Unsigned integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.execve.args Program arguments Character string 2.0.0 to 3.6.8
sysdig.param.execve.cgroups cgroups Byte sequence 2.0.0 to 3.6.8
sysdig.param.execve.comm Command Character string 2.0.0 to 3.6.8
sysdig.param.execve.cwd Current working directory Character string 2.0.0 to 3.6.8
sysdig.param.execve.env env Character string 2.0.0 to 3.6.8
sysdig.param.execve.exe exe Character string 2.0.0 to 3.6.8
sysdig.param.execve.fdlimit fdlimit Unsigned integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.execve.filename filename Character string 3.2.0 to 3.6.0
sysdig.param.execve.loginuid loginuid Signed integer (4 bytes) 3.2.0 to 3.6.8
sysdig.param.execve.pgft_maj pgft_maj Unsigned integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.execve.pgft_min pgft_min Unsigned integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.execve.pid pid Byte sequence 2.0.0 to 3.0.14
sysdig.param.execve.ptid ptid Byte sequence 2.0.0 to 3.6.8
sysdig.param.execve.tid tid Byte sequence 2.0.0 to 3.6.8
sysdig.param.execve.tty tty Signed integer (4 bytes) 3.2.0 to 3.6.8
sysdig.param.execve.vm_rss vm_rss Unsigned integer (4 bytes) 2.0.0 to 3.6.8
sysdig.param.execve.vm_size vm_size Unsigned integer (4 bytes) 2.0.0 to 3.6.8
sysdig.param.execve.vm_swap vm_swap Unsigned integer (4 bytes) 2.0.0 to 3.6.8
sysdig.param.fchmod.mode mode Byte sequence 3.6.1 to 3.6.8
sysdig.param.fchmodat.filename filename Byte sequence 3.6.1 to 3.6.8
sysdig.param.fcntl.res res Signed integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.flock.operation operation Byte sequence 2.0.0 to 3.6.8
sysdig.param.futex.op op Byte sequence 2.0.0 to 3.6.8
sysdig.param.futex.val val Unsigned integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.getgid.gid gid Byte sequence 2.0.0 to 3.6.8
sysdig.param.getresgid.egid egid Byte sequence 2.0.0 to 3.6.8
sysdig.param.getresgid.rgid rgid Byte sequence 2.0.0 to 3.6.8
sysdig.param.getresgid.sgid sgid Byte sequence 2.0.0 to 3.6.8
sysdig.param.getresuid.euid euid Byte sequence 2.0.0 to 3.6.8
sysdig.param.getresuid.ruid ruid Byte sequence 2.0.0 to 3.6.8
sysdig.param.getresuid.suid suid Byte sequence 2.0.0 to 3.6.8
sysdig.param.getsockopt.level level Byte sequence 3.2.0 to 3.6.8
sysdig.param.getsockopt.optlen optlen Unsigned integer (4 bytes) 3.2.0 to 3.6.8
sysdig.param.getsockopt.optname optname Byte sequence 3.2.0 to 3.6.8
sysdig.param.getsockopt.val val Byte sequence 3.2.0 to 3.6.8
sysdig.param.getuid.uid uid Byte sequence 2.0.0 to 3.6.8
sysdig.param.infra.description description Character string 3.2.0 to 3.6.8
sysdig.param.infra.name name Character string 3.6.1 to 3.6.8
sysdig.param.infra.scope scope Character string 3.2.0 to 3.6.8
sysdig.param.infra.source source Character string 3.2.0 to 3.6.8
sysdig.param.ioctl.argument I/O control: argument Unsigned integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.ioctl.request I/O control: request Unsigned integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.len Parameter length Unsigned integer (2 bytes) 2.0.0 to 3.6.8
sysdig.param.lens Parameter lengths Byte sequence 2.0.0 to 3.6.8
sysdig.param.link.newpath newpath Character string 3.6.1 to 3.6.8
sysdig.param.link.oldpath oldpath Character string 3.6.1 to 3.6.8
sysdig.param.linkat.flags flags Byte sequence 3.2.0 to 3.6.0
sysdig.param.linkat.newdir newdir Signed integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.linkat.newpath newpath Character string 3.2.0 to 3.6.0
sysdig.param.linkat.olddir olddir Signed integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.linkat.oldpath oldpath Character string 3.2.0 to 3.6.0
sysdig.param.linkat.res res Byte sequence 3.2.0 to 3.6.0
sysdig.param.listen.backlog backlog Unsigned integer (4 bytes) 2.0.0 to 3.6.8
sysdig.param.llseek.whence whence Byte sequence 2.0.0 to 3.6.8
sysdig.param.mkdirat.path path Byte sequence 3.2.0 to 3.6.8
sysdig.param.mmap2.pgoffset pgoffset Unsigned integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.mmap2.prot prot Byte sequence 2.0.0 to 3.6.8
sysdig.param.mmap2.res res Unsigned integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.mount.dev dev Character string 2.0.0 to 3.6.8
sysdig.param.mount.dir dir Character string 2.0.0 to 3.6.8
sysdig.param.mount.type type Character string 2.0.0 to 3.6.8
sysdig.param.munmap.addr addr Unsigned integer (8 bytes) 2.0.0 to 3.0.14
sysdig.param.munmap.length length Unsigned integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.nanosleep.interval interval Byte sequence 2.0.0 to 3.6.8
sysdig.param.notification.desc desc Character string 3.2.0 to 3.6.8
sysdig.param.notification.id id Character string 3.2.0 to 3.6.8
sysdig.param.openat.dev dev Unsigned integer (4 bytes) 3.2.0 to 3.6.8
sysdig.param.openat.dirfd dirfd Signed integer (8 bytes) 3.2.0 to 3.6.0
sysdig.param.openat.fd fd Signed integer (8 bytes) 3.2.0 to 3.6.0
sysdig.param.openat.mode mode Unsigned integer (4 bytes) 2.0.0 to 3.6.0
sysdig.param.openat.name name Character string 3.2.0 to 3.6.0
sysdig.param.openat2.dirfd dirfd Signed integer (8 bytes) 3.6.1 to 3.6.8
sysdig.param.openat2.fd fd Signed integer (8 bytes) 3.6.1 to 3.6.8
sysdig.param.openat2.flags flags Byte sequence 3.6.1 to 3.6.8
sysdig.param.openat2.mode mode Unsigned integer (4 bytes) 3.6.1 to 3.6.8
sysdig.param.openat2.name name Byte sequence 3.6.1 to 3.6.8
sysdig.param.openat2.resolve resolve Byte sequence 3.6.1 to 3.6.8
sysdig.param.page_fault.addr addr Unsigned integer (8 bytes) 3.2.0 to 3.6.8
sysdig.param.page_fault.error error Byte sequence 3.2.0 to 3.6.8
sysdig.param.page_fault.ip ip Unsigned integer (8 bytes) 3.2.0 to 3.6.8
sysdig.param.pipe.fd1 fd1 Signed integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.pipe.fd2 fd2 Signed integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.pipe.ino ino Unsigned integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.pluginevent.event_data event_data Byte sequence 3.6.1 to 3.6.8
sysdig.param.pluginevent.plugin_ID plugin_ID Unsigned integer (4 bytes) 3.6.1 to 3.6.8
sysdig.param.poll.timeout timeout Signed integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.ppoll.fds fds Byte sequence 2.0.0 to 3.6.8
sysdig.param.ppoll.sigmask sigmask Byte sequence 2.0.0 to 3.6.8
sysdig.param.ppoll.timeout timeout Byte sequence 2.0.0 to 3.6.8
sysdig.param.prlimit.newcur newcur Signed integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.prlimit.newmax newmax Signed integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.prlimit.oldcur oldcur Signed integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.prlimit.oldmax oldmax Signed integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.prlimit.resource resource Byte sequence 2.0.0 to 3.6.8
sysdig.param.procexit.core core Unsigned integer (1 byte) 3.6.1 to 3.6.8
sysdig.param.procexit.ret ret Byte sequence 3.6.1 to 3.6.8
sysdig.param.procexit.status status Byte sequence 2.0.0 to 3.6.8
sysdig.param.procinfo.cpu_sys cpu_sys Unsigned integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.procinfo.cpu_usr cpu_usr Unsigned integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.ptrace.addr addr Byte sequence 2.0.0 to 3.6.8
sysdig.param.ptrace.data data Byte sequence 2.0.0 to 3.6.8
sysdig.param.ptrace.request request Byte sequence 2.0.0 to 3.6.8
sysdig.param.pwritev.pos pos Unsigned integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.pwritev.size size Unsigned integer (4 bytes) 2.0.0 to 3.6.8
sysdig.param.quotactl.dqb_bhardlimit dqb_bhardlimit Unsigned integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.quotactl.dqb_bsoftlimit dqb_bsoftlimit Unsigned integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.quotactl.dqb_btime dqb_btime Byte sequence 2.0.0 to 3.6.8
sysdig.param.quotactl.dqb_curspace dqb_curspace Unsigned integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.quotactl.dqb_ihardlimit dqb_ihardlimit Unsigned integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.quotactl.dqb_isoftlimit dqb_isoftlimit Unsigned integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.quotactl.dqb_itime dqb_itime Byte sequence 2.0.0 to 3.6.8
sysdig.param.quotactl.dqi_bgrace dqi_bgrace Byte sequence 2.0.0 to 3.6.8
sysdig.param.quotactl.dqi_flags dqi_flags Byte sequence 2.0.0 to 3.6.8
sysdig.param.quotactl.dqi_igrace dqi_igrace Byte sequence 2.0.0 to 3.6.8
sysdig.param.quotactl.id id Unsigned integer (4 bytes) 2.0.0 to 3.6.8
sysdig.param.quotactl.quota_fmt quota_fmt Byte sequence 2.0.0 to 3.6.8
sysdig.param.quotactl.quota_fmt_out quota_fmt_out Byte sequence 2.0.0 to 3.6.8
sysdig.param.quotactl.quotafilepath quotafilepath Character string 2.0.0 to 3.6.8
sysdig.param.quotactl.special special Character string 2.0.0 to 3.6.8
sysdig.param.quotactl.type type Byte sequence 2.0.0 to 3.6.8
sysdig.param.renameat.newdirfd newdirfd Signed integer (8 bytes) 2.0.0 to 3.6.0
sysdig.param.renameat.newpath newpath Character string 2.0.0 to 3.0.14
sysdig.param.renameat.olddirfd olddirfd Signed integer (8 bytes) 2.0.0 to 3.6.0
sysdig.param.renameat.oldpath oldpath Character string 2.0.0 to 3.0.14
sysdig.param.renameat2.newdirfd newdirfd Signed integer (8 bytes) 3.6.1 to 3.6.8
sysdig.param.renameat2.newpath newpath Byte sequence 3.6.1 to 3.6.8
sysdig.param.renameat2.olddirfd olddirfd Signed integer (8 bytes) 3.6.1 to 3.6.8
sysdig.param.renameat2.oldpath oldpath Byte sequence 3.6.1 to 3.6.8
sysdig.param.seccomp.op op Unsigned integer (8 bytes) 3.2.0 to 3.6.8
sysdig.param.semctl.cmd cmd Byte sequence 2.0.0 to 3.6.8
sysdig.param.semctl.semid semid Signed integer (4 bytes) 2.0.0 to 3.6.8
sysdig.param.semctl.semnum semnum Signed integer (4 bytes) 2.0.0 to 3.6.8
sysdig.param.semctl.val val Signed integer (4 bytes) 2.0.0 to 3.6.8
sysdig.param.semget.key key Signed integer (4 bytes) 3.2.0 to 3.6.8
sysdig.param.semget.nsems nsems Signed integer (4 bytes) 3.2.0 to 3.6.8
sysdig.param.semget.semflg semflg Byte sequence 3.2.0 to 3.6.8
sysdig.param.semop.nsops nsops Unsigned integer (4 bytes) 2.0.0 to 3.6.8
sysdig.param.semop.sem_flg_0 sem_flg_0 Byte sequence 2.0.0 to 3.6.8
sysdig.param.semop.sem_flg_1 sem_flg_1 Byte sequence 2.0.0 to 3.6.8
sysdig.param.semop.sem_num_0 sem_num_0 Unsigned integer (2 bytes) 2.0.0 to 3.6.8
sysdig.param.semop.sem_num_1 sem_num_1 Unsigned integer (2 bytes) 2.0.0 to 3.6.8
sysdig.param.semop.sem_op_0 sem_op_0 Signed integer (2 bytes) 2.0.0 to 3.6.8
sysdig.param.semop.sem_op_1 sem_op_1 Signed integer (2 bytes) 2.0.0 to 3.6.8
sysdig.param.sendfile.in_fd in_fd Signed integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.sendfile.offset offset Unsigned integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.sendfile.out_fd out_fd Signed integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.sendfile.size size Unsigned integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.setns.nstype nstype Byte sequence 2.0.0 to 3.6.8
sysdig.param.setpgid.pgid pgid Byte sequence 3.2.0 to 3.6.8
sysdig.param.setpgid.pid pid Byte sequence 3.2.0 to 3.6.8
sysdig.param.setrlimit.cur cur Signed integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.setrlimit.max max Signed integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.shutdown.how how Byte sequence 2.0.0 to 3.6.8
sysdig.param.signaldeliver.dpid dpid Byte sequence 2.0.0 to 3.6.8
sysdig.param.signaldeliver.sig sig Byte sequence 2.0.0 to 3.6.8
sysdig.param.signaldeliver.spid spid Byte sequence 2.0.0 to 3.6.8
sysdig.param.signalfd.mask mask Unsigned integer (4 bytes) 2.0.0 to 3.6.8
sysdig.param.socketpair.domain domain Byte sequence 2.0.0 to 3.6.8
sysdig.param.socketpair.peer peer Unsigned integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.socketpair.proto proto Unsigned integer (4 bytes) 2.0.0 to 3.6.8
sysdig.param.socketpair.source source Unsigned integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.splice.fd_in fd_in Signed integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.splice.fd_out fd_out Signed integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.switch.next next Byte sequence 2.0.0 to 3.6.8
sysdig.param.symlink.linkpath linkpath Character string 3.6.1 to 3.6.8
sysdig.param.symlinkat.linkdirfd linkdirfd Signed integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.symlinkat.linkpath linkpath Byte sequence 2.0.0 to 3.6.8
sysdig.param.symlinkat.target target Character string 2.0.0 to 3.6.8
sysdig.param.syscall.ID ID Byte sequence 2.0.0 to 3.6.8
sysdig.param.syscall.nativeID nativeID Unsigned integer (2 bytes) 2.0.0 to 3.6.8
sysdig.param.sysdigevent.event_data event_data Unsigned integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.sysdigevent.event_type event_type Unsigned integer (4 bytes) 2.0.0 to 3.6.8
sysdig.param.timerfd_create.clockid clockid Unsigned integer (1 byte) 2.0.0 to 3.6.8
sysdig.param.tracer.id id Signed integer (8 bytes) 3.2.0 to 3.6.8
sysdig.param.tracer.tags tags Byte sequence 3.2.0 to 3.6.8
sysdig.param.umount.flags flags Byte sequence 2.0.0 to 3.0.14
sysdig.param.umount.name name Character string 2.0.0 to 3.0.14
sysdig.param.umount.res res Byte sequence 2.0.0 to 3.0.14
sysdig.param.unlink.path path Character string 2.0.0 to 3.0.14, 3.6.1 to 3.6.8
sysdig.param.unlinkat.dirfd dirfd Signed integer (8 bytes) 2.0.0 to 3.0.14
sysdig.param.userfaultfd.res res Byte sequence 3.6.1 to 3.6.8
sysdig.param.vfork.fdlimit fdlimit Signed integer (8 bytes) 2.0.0 to 3.6.8
sysdig.param.vfork.gid gid Unsigned integer (4 bytes) 2.0.0 to 3.6.8
sysdig.param.vfork.uid uid Unsigned integer (4 bytes) 2.0.0 to 3.6.8
sysdig.param.vfork.vpid vpid Byte sequence 2.0.0 to 3.6.8
sysdig.param.vfork.vtid vtid Byte sequence 2.0.0 to 3.6.8
sysdig.thread_id Thread ID Unsigned integer (8 bytes) 2.0.0 to 3.6.8