Ask Your Question

Revision history [back]

This is a classic case for using tshark with the -T fields option. With a display filter set so that only answers are shown:

tshark -r <yourcapture> -Y "dns.count.answers > 0" -T fields -e -e

replacing <yourcapture> with the path to the capture file.

Output looks like this, with first the query, then the answer(s):,,,

Note in this case there were multiple answer records for the query, all comma separated.