• g


    7 months ago
    Hi, I'm running osquery on linux with process auditing via eBPF enabled. I've been using to check performance stats and I'm getting the same ~20% cpu usage results regardless of how many execs/s I run. I'm unsure if I'm missing something but I can't find any documentation that suggests CPU usage is limited to max 20%? I'm not very knowledgeable on Linux performance testing so it's quite possible I may have something configured wrong.
  • zwass


    7 months ago
    cc @alessandrogario
  • s


    7 months ago
    There’s a pretty large performance bug around ebpf in 5.0. Checkout