Learn packet analysis with challenging Wireshark labs (+25 advanced PCAP case-studies) !

DNS View

The extended PCAP list view allows you directly explore domain names.

Features

DNS View

The DNS view gives you a quick insight between which hosts the communication is happening

  • ⚡️ DNS and IP address DNS and IP mapping is shown in a table view
  • ⚡️ Aggregation To quickly drill down the results aggregation is supported
  • ⚡️ Interactive Quickly filter the correct trace and packets

Aggregate

To aggregate press the activate button at the top of the DNS table

DNS View Grouped

Filter packets

You can filter packets directly by DNS name or IP name by clicking on the respective table entries. The resulting display filter considers TLS SNIs as well as IP names.

Limitations

Currently, the DNS view has the following limitations

  • does not support LLMNR, NetBIOS
  • does not support filtering on the above
  • does not fully support IPv6