How can I use tcpdump effectively?
First, you may want to consider using ethereal instead of tcpdump. Ethereal is an X-based (there’s also a Windows port) graphical dump engine. Because of the graphical nature you can slice the data differently, and take advantage of features like the TCP flow reassembly. Ethereal can capture directly, or it can be used to look at a tcpdump output file. This can be used effectively to dump on a server or other probe and analyze on the local workstation.