Q: Your company just acquired a massive monolithic C++ application built 15 years ago. It emits zero metrics and no useful logs. The developers left the company, and re-compiling the code is too dangerous. How do you gain deep observability into its network calls and database queries?
When you cannot modify the application code (zero-instrumentation), you use eBPF-based observability.
🛠️ Production Runbook & Step-by-Step Resolution
Production Solution & Architecture
When you cannot modify the application code (zero-instrumentation), you use eBPF-based observability. eBPF allows executing sandboxed programs directly inside the Linux kernel. Using tools like Pixie, Cilium Hubble, or Datadog Universal Service Monitoring, an eBPF agent running on the host node attaches probes to kernel-level sockets (tcp_sendmsg, tcp_recvmsg). It can intercept and parse the raw plaintext network packets (HTTP, DNS, MySQL protocols) right as they enter/leave the application, dynamically generating RED metrics (Request rates, Errors, Durations) and distributed traces for the legacy monolith without changing a single line of its original C++ code.
- Immediate Triage: When you cannot modify the application code (zero-instrumentation), you use eBPF-based observab
- Run targeted verification commands before modifying configuration.
- Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.