tcpdump auf Sophos UMT - Linux Shell, How can I find a communication to IP Are there other methods?

Hi all,

Since days we have the following entries in the Advanced Thread Protection

We want to find out which host in our network is communicating to IP over a Unix/Linux shell with 
the command

tcpdump -nei any port 53 dst -n -s0 -w /var/sec/chroot-httpd/var/webadmin/tcpdump.pcap

Is this a way? Are there any other ways?