Dumping packets from anywhere in the networking stack

208 · Red Hat · Jan. 9, 2025, 7:36 a.m.
Summary
This blog post explains how packet capturing works in Linux using tools like tcpdump and Wireshark, detailing their limitations and how the new tool Retis can enhance packet visibility from various points in the networking stack. It emphasizes the techniques to capture packets at different networking layers and how Retis can complement existing tools by converting captured data to the pcap format for use with tcpdump and Wireshark.