| 1 | # The `ebpf load mode` option accepts the following values : |
| 2 | # `entry` : The eBPF collector only monitors calls for the functions, and does not show charts related to errors. |
| 3 | # `return : In the `return` mode, the eBPF collector monitors the same kernel functions as `entry`, but also creates |
| 4 | # new charts for the return of these functions, such as errors. |
| 5 | # |
| 6 | # The eBPF collector also creates charts for each running application through an integration with the `apps.plugin` |
| 7 | # or `cgroups.plugin`. |
| 8 | # If you want to disable the integration with `apps.plugin` or `cgroups.plugin` along with the above charts, change |
| 9 | # the setting `apps` and `cgroups` to 'no'. |
| 10 | # |
| 11 | # The `pid table size` defines the maximum number of PIDs stored inside the hash table. |
| 12 | # |
| 13 | # The `maps per core` defines if hash tables will be per core or not. This option is ignored on kernels older than 4.6. |
| 14 | # |
| 15 | # The `lifetime` defines the time length a thread will run when it is enabled by a function. |
| 16 | # |
| 17 | [global] |
| 18 | # ebpf load mode = entry |
| 19 | # update every = 1 |
| 20 | ebpf type format = auto |
| 21 | ebpf co-re tracing = trampoline |
| 22 | collect pid = real parent |
| 23 | lifetime = 300 |