This wiki has been migrated to and is now deprecated. Please use that site instead.

Linux netlink (netlink)

Linux netlink is a communication channel between Linux kernel space and user space. [To be extended].


The netlink socket interface appeared in Linux kernel 2.2.

Protocol dependencies

Example traffic

XXX - Add example decoded traffic for this protocol here (as plain text or Wireshark screenshot).


The netlink dissector is fully functional, although not all netlink families are dissected.

Preference Settings

The netlink dissector has no preference settings.

Example capture file

XXX - Add a simple example capture file to the SampleCaptures page and link from here (see below). Keep this file short, it's also a good idea to gzip it to make it even smaller, as Wireshark can open gzipped files automatically.

Display Filter

A complete list of netlink display filter fields can be found in the display filter reference

Capture Filter

You cannot directly filter netlink protocols while capturing.


Protocols/netlink (last edited 2020-01-16 19:51:28 by JaapKeuter)