pcap_open_live(3) pcap_open_live(3)
NAME
pcap_open_live - open a device for capturing
SYNOPSIS
#include <pcap/pcap.h>
char errbuf[PCAP_ERRBUF_SIZE];
pcap_open_live(3) char *device, int snaplen,
int promisc, int to_ms, char *errbuf);
DESCRIPTION
pcap_open_live() is used to obtain a packet capture handle to capture
packets on a device (typically a network interface, see
pcap_findalldevs(3) for a more detailed explanation). device is a
string that specifies the capture device to open; in this function, a
null pointer means the same as the string "any".
snaplen specifies the snapshot length to be set on the handle. If the
packet data should not be truncated at the end, a value of 262144
should be sufficient for most devices, but D-Bus devices require a
value of 128MiB (128*1024*1024).
promisc specifies whether the device is to be put into promiscuous
mode. If promisc is non-zero, promiscuous mode will be set, otherwise
it will not be set.
to_ms specifies the packet buffer timeout, as a non-negative value, in
milliseconds. (See pcap(3) for an explanation of the packet buffer
timeout.)
errbuf is a buffer large enough to hold at least PCAP_ERRBUF_SIZE
chars.
RETURN VALUE
pcap_open_live() returns a pcap_t * on success and a null pointer on
failure. If a null pointer is returned, errbuf is filled in with an
appropriate error message. errbuf may also be set to warning text when
pcap_open_live() succeeds; to detect this case the caller should store
a zero-length string in errbuf before calling pcap_open_live() and
display the warning to the user if errbuf is no longer a zero-length
string.
SEE ALSO
pcap_create(3), pcap_activate(3)
6 September 2026 pcap_open_live(3)
libpcap 1.11.0 - Generated Tue Sep 15 08:52:05 CDT 2026
