eBPF has revolutionized Linux observability by running sandboxed programs inside the kernel. Here are my operational notes from profiling network socket events.