pcap-linktype(7) Miscellaneous Information Manual pcap-linktype(7)
NAME
pcap-linktype - link-layer header types supported by libpcap
DESCRIPTION
For a live capture or ``savefile'', libpcap supplies, as the return
value of the pcap_datalink(3) routine, a value that indicates the
type of link-layer header at the beginning of the packets it provides.
This is not necessarily the type of link-layer header that the packets
being captured have on the network from which they're being captured;
for example, packets from an IEEE 802.11 network might be provided by
libpcap with Ethernet headers that the network adapter or the network
adapter driver generates from the 802.11 headers. The names for those
values begin with DLT_, so they are sometimes called "DLT_ values".
The pcap_datalink_val_to_name(3) and
pcap_datalink_name_to_val(3) routines can be used to translate
between DLT_ values and names. Some capture devices support more than
one link-layer header type. The pcap_list_datalinks(3) routine can
be used to retrieve the supported link-layer header types of a capture
device and the pcap_set_datalink(3) routine can be used to change
the link-layer header type of a capture device.
The values stored in the link-layer header type field in the savefile
header are, in most but not all cases, the same as the values returned
by pcap_datalink(). The names for those values begin with LINKTYPE_.
The link-layer header types supported by libpcap are described at
https://www.tcpdump.org/linktypes.html .
SEE ALSO
pcap(3)
1 October 2024 pcap-linktype(7)
libpcap 1.11.0 - Generated Tue Sep 15 09:59:28 CDT 2026
