#Get help here http://www.sysdig.org/wiki/sysdig-user-guide/
sudo sysdig evt.type=open and fd.name contains /etc
*%evt.num %evt.time %evt.cpu %proc.name (%thread.tid) %evt.dir %evt.type %evt.args
sysdig proc.name=asdfg and proc.name!=petre
#Get help here http://www.sysdig.org/wiki/sysdig-user-guide/
sudo sysdig evt.type=open and fd.name contains /etc
*%evt.num %evt.time %evt.cpu %proc.name (%thread.tid) %evt.dir %evt.type %evt.args
sysdig proc.name=asdfg and proc.name!=petre