How to show exact process name that wrote to disk?


I am new to netdata and wonder if it is possible to see the process name that wrote to disk at a specific time. In this example, a process has written a lot of stuff to disk at 17:42:06, but the graph only shows “other”. How can I see the exact process name that caused this disk load?

My system:

These charts are created by the so-called apps.plugin, which groups processes based on the process tree. You can customize the apps groupings, by going into /etc/netdata and running ./edit-config apps_groups.conf.

You can see my own modifications in this gist.

Hello Ralph,

thank you for your reply!

Unfortunately, this does not help, since this only works on processes which I am aware of. There are many users on the system, and they can basically work on their own, have their own batch scripts, etc. So, when a user is running a process which requires a lot of CPU and Disk usage, I would be interested in knowing which script this is. And if it is not running anymore, then I cannot see it in top or htop , so my hope was that I can see the process name in netdata’s history. Is there any “forensics” possible, any CSV export I can do, or do I really need to add every executable file (i.e. all files which have chmod +x) on the whole system into apps_groups.conf ?

