in reply to real-time packet capture
You may find that snort will do much of what you want.
It should work perfectly the first time! - toma