Capture and Analyze Android Network Logs with ADB

13 min read Step‑by‑step guide to enable NetLog on Android, capture network traffic with ADB, and interpret the data to troubleshoot connectivity issues. September 27, 2026 19:00 How to Capture and Analyze Android Network Logs with ADB (NetLog)

Why you might need a NetLog

When an app or a system service cannot reach the internet, the usual suspects—Wi‑Fi signal, carrier data, or a mis‑behaving VPN—are easy to check. However, many connectivity problems stem from DNS failures, TCP retransmissions, or malformed packets that are invisible in the standard Settings > Network diagnostics screen. Android’s NetLog feature records low‑level network events (socket creation, DNS queries, TCP state changes, etc.) in a binary file that can be inspected with Android Studio’s Network Profiler or third‑party parsers. By capturing a NetLog you get a timeline of exactly what the OS tried to do, which often reveals the root cause of “Why can’t I load this page?” or “Why does my app keep timing out?”

Before you start

  • Computer with ADB installed – The Android SDK Platform‑Tools package provides the adb binary. It works on Windows, macOS, and Linux.
  • USB cable (or Wi‑Fi ADB) – A reliable connection prevents intermittent data loss during the capture.
  • Device charge ≥ 50 % – NetLog can generate several megabytes of data quickly.
  • Free storage on the device – Allocate at least 50 MB in /sdcard/ for the log file.
  • Optional: Android Studio – The built‑in Network Profiler makes visual analysis easier, but you can also use the free netlog2json script.

If any of these items are missing, pause and acquire them now. Skipping a prerequisite often leads to incomplete logs or a failed capture.

Step 1 – Enable Developer Options and USB Debugging

  1. Open Settings on the Android device.
  2. Scroll to About phone (or About tablet).
  3. Tap Build number seven times. You’ll see a toast: “You are now a developer!”
  4. Return to the main Settings page; a new entry Developer options appears.
  5. Enter Developer options and toggle USB debugging on.
  6. If you plan to capture logs over Wi‑Fi, also enable Wireless debugging (Android 11+).

Why this matters: ADB communicates with the device through a debugging bridge. Without USB debugging, adb cannot issue the netlog command.

Step 2 – Grant the NetLog permission (Android 10+)

Starting with Android 10, NetLog is considered a privileged operation. The system will prompt the user to allow “Network logging” the first time you run the command. You must confirm this dialog; otherwise the command silently fails.

  1. Connect the device to the computer via USB (or ensure both are on the same Wi‑Fi network for wireless ADB).
  2. Open a terminal/command prompt on the computer and verify the connection:
    adb devices
    You should see the device’s serial number with the word device.
  3. Run a harmless command to trigger the permission dialog, e.g.:
    adb shell dumpsys activity
    When the dialog appears on the phone, tap Allow.

After the permission is granted once, Android remembers it for the lifetime of the user profile, so you won’t be asked again for subsequent captures.

Step 3 – Choose a destination path for the log file

NetLog writes a binary .bin file to the location you specify. It’s best to store it on the primary external storage (/sdcard/) because pulling files from there is straightforward.

  1. Decide on a filename, for example netlog_2024_09_27.bin.
  2. Full path: /sdcard/Android/netlog_2024_09_27.bin.
  3. If the Android folder does not exist, create it with:
    adb shell mkdir -p /sdcard/Android

Step 4 – Start the NetLog capture

  1. Run the following command:
    adb shell netlog -o /sdcard/Android/netlog_2024_09_27.bin
    The terminal will return immediately, but the device is now recording every network event.
  2. Do not disconnect the device while the capture is active.
  3. Reproduce the problem on the phone – open the app that is failing, navigate to the problematic screen, or toggle Wi‑Fi off/on, etc. The more activity you generate, the richer the log.
  4. When you have captured enough data (usually 30 seconds to 2 minutes), stop the logging by pressing Ctrl+C in the terminal.
    ^C
    The device finalises the file and you’ll see a line like “NetLog written to /sdcard/Android/...”.

Why you stop manually: NetLog does not have a built‑in timeout; leaving it running can quickly fill the storage and degrade performance.

Step 5 – Pull the log file to your computer

  1. Use ADB to copy the file:
    adb pull /sdcard/Android/netlog_2024_09_27.bin ./netlog_2024_09_27.bin
    The file will appear in the current directory.
  2. Optional: Verify the size (a few MB is typical). If the file is 0 KB, the capture likely never started – revisit Step 4.

Step 6 – Convert the binary NetLog to a readable format

Android Studio can open the binary directly, but many users prefer a JSON view. The Android Open Source Project provides a small Python script called netlog_to_json.py. Below is a quick way to use it without installing the full Android source.

  1. Download the script from the AOSP repository (search for netlog_to_json.py). Save it next to the .bin file.
  2. Make sure Python 3 is installed, then run:
    python3 netlog_to_json.py netlog_2024_09_27.bin > netlog_2024_09_27.json
  3. The resulting .json file contains an array of events with timestamps, event types, and payload data.

If you prefer a graphical view, skip the conversion and open the .bin directly in Android Studio’s Profiler → Network panel. Choose “Import…”, select the file, and the timeline appears.

Step 7 – Analyze the data

Below are common patterns to look for. Use the JSON viewer of your choice (VS Code, jq, or a web‑based formatter) and search for the fields that match the symptom you’re investigating.

7.1 DNS failures

  • Event type: DnsLookupStart followed quickly by DnsLookupFailed.
  • Check the hostname field – if it’s your app’s API endpoint, the DNS server may be unreachable.
  • Resolution: Verify the device’s DNS settings (Settings → Network → Private DNS) or try a public resolver like 1.1.1.1.

7.2 TCP retransmissions

  • Look for repeated TcpSend events with the same seq number.
  • High retransmission counts often indicate a weak Wi‑Fi signal or a mis‑behaving firewall.
  • Resolution: Move closer to the router, disable aggressive power‑saving Wi‑Fi modes, or test on mobile data.

7.3 TLS handshake errors

  • Events: TlsHandshakeStart → TlsHandshakeFailed.
  • The error_code field may read SSL_ERROR_BAD_CERTIFICATE or SSL_ERROR_HANDSHAKE_FAILURE.
  • Resolution: Check the device date/time (TLS is time‑sensitive) and ensure the server’s certificate chain is trusted.

7.4 Unexpected network interface switches

  • Event: NetworkChange indicating a switch from WIFI to MOBILE or vice‑versa.
  • If the switch happens mid‑request, the app may see a “connection reset”.
  • Resolution: Disable “Smart network switch” or set the app’s android:usesCleartextTraffic flag appropriately.

These examples cover the majority of connectivity complaints. The full NetLog contains many more event types; the AOSP documentation lists them if you need deeper digging.

Alternative ways to view NetLog

  • Chrome DevTools – Open chrome://inspect, select the device, and use the “Network” tab to import the .bin file.
  • Wireshark – Convert the NetLog to PCAP using the netlog2pcap utility (available in the Android SDK’s platform-tools folder). Then open the PCAP in Wireshark for packet‑level analysis.
  • Third‑party apps – Some Play Store utilities (e.g., “NetLog Viewer”) can read the binary directly without a PC.

Troubleshooting common problems

Problem 1 – “netlog: command not found”

Older Android versions (pre‑Android 10) do not ship the netlog binary. In that case you can fall back to adb shell logcat -b all -s ConnectivityService which records similar information in plain text, albeit without the detailed socket timeline.

Problem 2 – Log file is empty or only a few kilobytes

  • Make sure you granted the “Network logging” permission when the prompt appeared.
  • Confirm that the device’s storage path is writable: adb shell ls -l /sdcard/Android.
  • Check that you actually generated network traffic while the logger was active.

Problem 3 – Pull fails with “permission denied”

Some OEMs restrict access to /sdcard/Android for non‑system apps. Use the run-as command with a rooted device, or store the file in /sdcard/Download instead.

Problem 4 – Android Studio cannot import the file

Make sure you are using Android Studio 4.2 or newer. Older versions lack NetLog support. Updating the IDE resolves the issue.

Safety and privacy considerations

  • NetLog captures every socket opened by every app, including URLs, IP addresses, and sometimes clear‑text payload headers. Treat the file as sensitive data.
  • Never share a NetLog publicly unless you have removed or redacted personally identifiable information (PII).
  • If you are troubleshooting a corporate device, verify that your organization’s policy permits capturing network logs.

Wrap‑up

By following the steps above you now have a reproducible workflow for capturing Android network activity, converting it to a readable format, and extracting actionable insights. The same process can be reused whenever a new app misbehaves, a VPN drops, or a DNS change causes outages. Remember to keep the device’s storage tidy—delete old .bin files after analysis—to avoid accidental data exposure.

User Comments (0)

Add Comment
We'll never share your email with anyone else.