Snooping TLS to get FQDNs gives you only hostnames, not full URLs.
Over 50% of the top million web sites automatically redirect visitors to HTTPS. Any URLs can only be read if you can install software or your own certificate on each monitored endpoint.