On linux, I can capture a pcap file on another host with tcpdump and pipe it live back to wireshark on the local machine:ssh host sudo tcpdump -iany -U -s0 -w - \'not
ssh host sudo tcpdump -iany -U -s0 -w - \'not