Display Filter Reference: PKTAP packet header

Protocol field name: pktap

Versions: 1.12.0 to 2.6.1

Back to Display Filter Reference

Field name Description Type Versions
pktap.cmdname Command name Character string 1.12.0 to 2.6.1
pktap.dlt DLT Unsigned integer, 4 bytes 1.12.0 to 2.6.1
pktap.ecmdname Effective command name Character string 1.12.0 to 2.6.1
pktap.epid Effective process ID Unsigned integer, 4 bytes 1.12.0 to 2.6.1
pktap.flags Flags Unsigned integer, 4 bytes 1.12.0 to 2.6.1
pktap.hdrlen Header length Unsigned integer, 4 bytes 1.12.0 to 2.6.1
pktap.hdrlen_too_short Header length is too short Label 1.12.0 to 2.6.1
pktap.ifname Interface name Character string 1.12.0 to 2.6.1
pktap.iftype Interface type Unsigned integer, 2 bytes 1.12.0 to 2.6.1
pktap.ifunit Interface unit Unsigned integer, 2 bytes 1.12.0 to 2.6.1
pktap.llhdrlen Link-layer header length Unsigned integer, 4 bytes 1.12.0 to 2.6.1
pktap.lltrlrlen Link-layer trailer length Unsigned integer, 4 bytes 1.12.0 to 2.6.1
pktap.pfamily Protocol family Unsigned integer, 4 bytes 1.12.0 to 2.6.1
pktap.pid Process ID Unsigned integer, 4 bytes 1.12.0 to 2.6.1
pktap.rectype Record type Unsigned integer, 4 bytes 1.12.0 to 2.6.1
pktap.svc_class Service class Unsigned integer, 4 bytes 1.12.0 to 2.6.1
Go Beyond with Riverbed Technology

Riverbed is Wireshark's primary sponsor and provides our funding. They also make great products that fully integrate with Wireshark.

I have a lot of traffic...

ANSWER: SteelCentral™ Packet Analyzer PE
  • • Visually rich, powerful LAN analyzer
  • • Quickly access very large pcap files
  • • Professional, customizable reports
  • • Advanced triggers and alerts
Learn More

Buy Now

No, really, I have a LOT of traffic…

ANSWER: SteelCentral™ NetShark appliance
  • • Troubleshoot problems faster
  • • Quickly identify the applications running on your network
  • • Monitor your virtual machine traffic
Learn More