Chapter 37
Postmortem Tracing
This chapter describes the DTrace facilities for postmortem extraction and processing of the
in-kernel data of DTrace consumers. In the event of a system crash, the
information that has been recorded with DTrace may provide the crucial clues to
root-cause the system failure. DTrace data may be extracted and processed from the
system crash dump to aid you in understanding fatal system failures. By coupling
these postmortem capabilities of DTrace with its ring buffering buffer policy (see Chapter 11, Buffers and Buffering),
DTrace can be used as an operating system analog to the black box flight
data recorder present on commercial aircraft.
To extract DTrace data from a specific crash dump, you should begin by
running the Solaris Modular Debugger, mdb(1), on the crash dump of interest.
The MDB module containing the DTrace functionality will be loaded automatically. To learn
more about MDB, refer to the Solaris Modular Debugger Guide.