Andrew Mercer
on this page

What it is

perf is the kernel's profiler. It samples what the CPU is executing, counts hardware events (cycles, cache misses), and records tracepoints. Brendan Gregg's perf examples page is the best reference.

sudo dnf install perf        # or apt-get install linux-tools-generic

Common commands

sudo perf top                                   # live view of hottest functions system-wide
sudo perf stat -d ./command                     # counters for one command (cycles, IPC, cache misses)
sudo perf stat -p <pid> sleep 10                # counters for a running process

sudo perf record -F 99 -a -g -- sleep 30        # sample all CPUs at 99 Hz with call graphs
sudo perf report                                # browse the recording
sudo perf script > out.perf                     # raw text, for flame graph tooling

Tracepoints

sudo perf list | grep block                     # what exists
sudo perf record -e block:block_rq_issue -ag    # block I/O issue events with stacks (Ctrl+C to stop)
sudo perf trace -p <pid>                        # strace-like, lower overhead

A flame graph turns perf script output into an interactive picture of where CPU time goes. See FlameGraph.

perf needs kernel.perf_event_paranoid to allow the access you want (or root). Debug symbols greatly improve results for compiled code. Related: strace, blktrace, turbostat.