pcap_create() is used to create a packet capture handle to look
at packets on the network. source is a string that specifies the
network device to open; on Linux systems with 2.2 or later
kernels, a source argument of "any" or NULL can be used to
capture packets from all interfaces.
The returned handle must be activated with pcap_activate(3PCAP)
before packets can be captured with it; options for the capture,
such as promiscuous mode, can be set on the handle before
pcap_create() returns a pcap_t * on success and NULL on failure.
If NULL is returned, errbuf is filled in with an appropriate
error message. errbuf is assumed to be able to hold at least
This page is part of the libpcap (packet capture library)
project. Information about the project can be found at
⟨http://www.tcpdump.org/⟩. If you have a bug report for this
manual page, see ⟨http://www.tcpdump.org/#patches⟩. This page
was obtained from the project's upstream Git repository
⟨https://github.com/the-tcpdump-group/libpcap.git⟩ on 2021-04-01.
(At that time, the date of the most recent commit that was found
in the repository was 2021-03-31.) If you discover any rendering
problems in this HTML version of the page, or you believe there
is a better or more up-to-date source for the page, or you have
corrections or improvements to the information in this COLOPHON
(which is not part of the original manual page), send a mail to
3 January 2014 PCAP_CREATE(3PCAP)