@pistolero @Penis Remover VIII Real time monitoring of TLS connections to a specific server then extracting the requested domain names (SNI) and enriching the output with a country lookup and a connection counter.
And there is more refinement to not overload CPU , to geo localisate new IP's
A display filter that further processes only packets containing the Server Name Indication (SNI) extension. This occurs during the TLS "Client Hello" handshake and reveals the domain name the client is trying to reach (e.g., git.freespeechextremist.com), even though the rest of the traffic is encrypted.
And, outputs the data in a simple two-column format: the Source IP and the Requested Domain Name.
Good string as WS or T-Shark operator.