Stop digging through ps aux when a process just vanished

Process & Resource Monitoring (Top/Htop/Ps/Systemd)

Stop digging through ps aux when a process just vanished

🧩 The Challenge

You’ve been staring at a process that keeps flapping or dying, but by the time you run ps, it’s already gone. It’s infuriating when you can’t catch the command line arguments before the process exits.

💡 The Fix

Use the audit framework to watch for process execution events in real-time. It’ll write exactly what happened to your logs, even if the process lasts for a fraction of a second.

auditctl -a exit,always -F arch=b64 -S execve
ausearch -sc execve

⚙️ Why It Works

This command tells the kernel to log every single execve system call, which is the heartbeat of starting any process on Linux. Since the kernel is doing the recording, nothing can hide from you by exiting too quickly.

🚀 Pro-Tip: Don’t forget to delete the rule with auditctl -d exit,always -F arch=b64 -S execve when you’re done, or you’ll fill your disk with noise.

Linux Tips & Tricks | © ngelinux.com | 10/3/2026

0 0 votes
Article Rating
Subscribe
Notify of
guest

0 Comments
Newest
Oldest Most Voted