My use of wireshark is only to monitor what sites my family is going to (incognito or not). I have my suspicions that incognito is being used and so I would like to figure out how to filter and capture searches and all urls being accessed on the network. I know very very little about network analysis and I'm in over my head trying to figure it out by myself. I downloaded Wireshark 101 Pdf file and I'm reading it but its like a foreign language. I just want to know how to filter out only what I'm looking for.
asked 14 Jun '14, 12:52
Although this is a Wireshark QA site, you may want to look into OpenDNS and put the OpenDNS servers into your router. You can then view reports of all the url lookups from your ISP connection.
If wanting to view this information in Wireshark, just filter on DNS traffic. Display filter is "dns", and capture filter would be "tcp port 53 or udp port 53"
answered 14 Jun '14, 19:49