如何统计指定用户短生命周期进程的CPU使用情况(AIX7.1/RHEL7)
Great question—tracking short-lived, high-frequency processes is tricky because tools like ps only capture snapshots, missing processes that start and exit between checks. Below are tailored solutions for RHEL 7 and AIX 7.1 that reliably capture CPU usage for these ephemeral processes.
RHEL 7 Solutions
Option 1: SystemTap Script (Real-Time Aggregation)
SystemTap is ideal here because it hooks into kernel events to track process start/exit and aggregate CPU usage in real time—no missed processes, and you get a clean summary at the end.
First, install prerequisites:
yum install systemtap kernel-devel-$(uname -r)
Create a script called short_proc_monitor.stp:
global cpu_time_per_user probe process.begin { # Record the user ID when a process starts user_uid = uid() } probe process.end { # Calculate total CPU time (user + system) in milliseconds total_cpu_ms = (utime() + stime()) / 1000 # Get the username from UID user_name = getuidname(uid()) # Add to the user's total cpu_time_per_user[user_name] += total_cpu_ms } probe timer.s($1) { # After $1 seconds, print results and exit printf("\nCPU Usage Summary (past %d seconds):\n", $1) foreach (user in cpu_time_per_user-) { # Convert ms to seconds for readability cpu_sec = cpu_time_per_user[user] / 1000.0 printf("User %s consumed %.2f seconds of CPU time\n", user, cpu_sec) } exit() }
Run it for your desired duration (e.g., 60 seconds):
stap short_proc_monitor.stp 60
This will output exactly what you need: a breakdown of total CPU time per user over the specified period.
Option 2: Auditd (Log-Based Tracking)
If SystemTap isn't available, use auditd to log process exit events with resource usage, then parse the logs for totals.
- Configure auditd to log exit events:
auditctl -a exit,always -F arch=b64 -S exit_group -F auid>=1000 -F auid!=4294967295
This logs exit events for non-system users.
- Start monitoring for N seconds (replace 60 with your duration):
sleep 60
- Parse logs to calculate total CPU time:
#!/bin/bash DURATION=60 sleep $DURATION ausearch -m exit -ts $DURATION seconds ago --format csv | awk -F',' ' BEGIN { print "CPU Usage Summary (past '$DURATION' seconds):" } $11 ~ /[0-9]+/ { cpu[$2] += $11 } END { for (user in cpu) { printf("User %s consumed %.2f seconds of CPU time\n", user, cpu[user]/1000) } } '
Note: Verify the CSV column index for CPU time with ausearch --format csv if your output differs.
AIX 7.1 Solutions
AIX's kernel trace facility is the most reliable way to track short-lived processes, as it captures every process start and exit event.
Option 1: Trace + trcrpt (Kernel-Level Tracking)
- Start a trace that captures exec/exit events and CPU usage:
trace -a -T 60 -o proc_trace.out -k exec,exit
-a: Trace all processes-T 60: Stop tracing after 60 seconds-o proc_trace.out: Save output to a file-k exec,exit: Target exec and exit kernel events
- Process the trace file to extract CPU usage per user:
trcrpt -o proc_summary.out -n proc_trace.out
Then parse the summary with awk:
awk ' BEGIN { print "CPU Usage Summary (past 60 seconds):" } $1 ~ /^[0-9]+/ && $5 ~ /^[a-z]/ { user[$5] += $7 } END { for (u in user) { printf("User %s consumed %.2f seconds of CPU time\n", u, user[u]/100) } } ' proc_summary.out
Explanation: AIX's trace reports CPU time in hundredths of a second, so dividing by 100 converts it to standard seconds. Adjust column indices if your trcrpt output format varies.
Option 2: procmon (Simpler Alternative)
If your system has procmon installed (part of bos.sysmgt.procmgr), use it for easier monitoring:
procmon -o procmon.out -t 60
Parse the output to aggregate CPU usage:
awk ' BEGIN { print "CPU Usage Summary (past 60 seconds):" } $3 == "EXIT" { user[$2] += $10 } END { for (u in user) { printf("User %s consumed %.2f seconds of CPU time\n", u, user[u]/100) } } ' procmon.out
Note: procmon requires root privileges to run.
Key Notes
- All methods need root access to capture kernel-level process events.
- For extremely high-frequency processes, SystemTap (RHEL) and AIX Trace are the most reliable—they won't miss any process start/exit events.
- The output matches your requested format:
User [username] in past [X] seconds consumed [Y] seconds of CPU time.
内容的提问来源于stack exchange,提问作者Dumb admin

