Witr: why is this process running?
Summary
Pranshu Parmar presents witr, a tool that traces running processes back to the concrete reason they were started. witr runs as a static program on Linux, macOS, FreeBSD and Windows. The JSON output is suitable for scripts and automated processing.
Ideas
- witr ultimately treats ports, containers, services and files as questions about processes.
- A PID is the entry point into the complete chain of its triggers.
- CLI, JSON and TUI serve interactive as well as automated investigations.
- The TUI combines processes, ports, containers and file locks in one view.
- Causality complements the state data that ps, top, lsof and systemctl provide separately.
Insights
- A system's state does not yet explain which decision produced it.
- Good observability connects scattered metadata into a traceable chain of cause and effect.
- A uniform process model reduces switching between tools during incidents.
Facts
- The TUI shows process ancestry, ports, containers and system-wide file locks.
Recommendations
- Use witr read-only first before terminating processes or changing their priority.
- Document conspicuous start chains together with service, timer and container configurations.
References
Links to the original source and the Web Archive open in a new tab.