You are reading a single comment by @Velocio and its replies.
Click here to read the full conversation.
-
DNSMasq is your friend.
http://www.thekelleys.org.uk/dnsmasq/doc.html
Configure it to be your DNS server, change your routers DNS to use it, and add logging: http://www.linuxquestions.org/questions/arch-29/where-can-i-look-to-see-where-dnsmasq-is-logging-queries-4175531370/
@Velocio, cheers for that and sounds like a good plan. I need to get into the position where my wireshark/tcpdump machine can see the traffic first though. Cheers