When an app or a system service cannot reach the internet, the usual suspects—Wi‑Fi signal, carrier data, or a mis‑behaving VPN—are easy to check. However, many connectivity problems stem from DNS failures, TCP retransmissions, or malformed packets that are invisible in the standard Settings > Network diagnostics screen. Android’s NetLog feature records low‑level network events (socket creation, DNS queries, TCP state changes, etc.) in a binary file that can be inspected with Android Studio’s Network Profiler or third‑party parsers. By capturing a NetLog you get a timeline of exactly what the OS tried to do, which often reveals the root cause of “Why can’t I load this page?” or “Why does my app keep timing out?”
adb binary. It works on Windows, macOS, and Linux./sdcard/ for the log file.netlog2json script.If any of these items are missing, pause and acquire them now. Skipping a prerequisite often leads to incomplete logs or a failed capture.
Why this matters: ADB communicates with the device through a debugging bridge. Without USB debugging, adb cannot issue the netlog command.
Starting with Android 10, NetLog is considered a privileged operation. The system will prompt the user to allow “Network logging” the first time you run the command. You must confirm this dialog; otherwise the command silently fails.
adb devices
You should see the device’s serial number with the word device.
adb shell dumpsys activity
When the dialog appears on the phone, tap Allow.
After the permission is granted once, Android remembers it for the lifetime of the user profile, so you won’t be asked again for subsequent captures.
NetLog writes a binary .bin file to the location you specify. It’s best to store it on the primary external storage (/sdcard/) because pulling files from there is straightforward.
netlog_2024_09_27.bin./sdcard/Android/netlog_2024_09_27.bin.
Android folder does not exist, create it with:
adb shell mkdir -p /sdcard/Android
adb shell netlog -o /sdcard/Android/netlog_2024_09_27.bin
The terminal will return immediately, but the device is now recording every network event.
^C
The device finalises the file and you’ll see a line like “NetLog written to /sdcard/Android/...”.
Why you stop manually: NetLog does not have a built‑in timeout; leaving it running can quickly fill the storage and degrade performance.
adb pull /sdcard/Android/netlog_2024_09_27.bin ./netlog_2024_09_27.bin
The file will appear in the current directory.
Android Studio can open the binary directly, but many users prefer a JSON view. The Android Open Source Project provides a small Python script called netlog_to_json.py. Below is a quick way to use it without installing the full Android source.
netlog_to_json.py). Save it next to the .bin file.python3 netlog_to_json.py netlog_2024_09_27.bin > netlog_2024_09_27.json
.json file contains an array of events with timestamps, event types, and payload data.
If you prefer a graphical view, skip the conversion and open the .bin directly in Android Studio’s Profiler → Network panel. Choose “Import…”, select the file, and the timeline appears.
Below are common patterns to look for. Use the JSON viewer of your choice (VS Code, jq, or a web‑based formatter) and search for the fields that match the symptom you’re investigating.
DnsLookupStart followed quickly by DnsLookupFailed.hostname field – if it’s your app’s API endpoint, the DNS server may be unreachable.1.1.1.1.TcpSend events with the same seq number.TlsHandshakeStart → TlsHandshakeFailed.error_code field may read SSL_ERROR_BAD_CERTIFICATE or SSL_ERROR_HANDSHAKE_FAILURE.NetworkChange indicating a switch from WIFI to MOBILE or vice‑versa.android:usesCleartextTraffic flag appropriately.These examples cover the majority of connectivity complaints. The full NetLog contains many more event types; the AOSP documentation lists them if you need deeper digging.
chrome://inspect, select the device, and use the “Network” tab to import the .bin file.
netlog2pcap utility (available in the Android SDK’s platform-tools folder). Then open the PCAP in Wireshark for packet‑level analysis.
Older Android versions (pre‑Android 10) do not ship the netlog binary. In that case you can fall back to adb shell logcat -b all -s ConnectivityService which records similar information in plain text, albeit without the detailed socket timeline.
adb shell ls -l /sdcard/Android.Some OEMs restrict access to /sdcard/Android for non‑system apps. Use the run-as command with a rooted device, or store the file in /sdcard/Download instead.
Make sure you are using Android Studio 4.2 or newer. Older versions lack NetLog support. Updating the IDE resolves the issue.
By following the steps above you now have a reproducible workflow for capturing Android network activity, converting it to a readable format, and extracting actionable insights. The same process can be reused whenever a new app misbehaves, a VPN drops, or a DNS change causes outages. Remember to keep the device’s storage tidy—delete old .bin files after analysis—to avoid accidental data exposure.









