Stephane Bortzmeyer writes: > I suggest: > > tshark <http://www.wireshark.org/docs/man-pages/tshark.html> and its > powerful DNS filter language > <http://www.wireshark.org/docs/dfref/d/dns.html> > > dnscap <https://www.dns-oarc.net/tools/dnscap> a pain to compile but > a very useful tool Very useful. Thanks. Arnt