Wireshark

Remote capture from Linux machine

plink.exe -ssh -pw <password> root@<server> "tcpdump -ni eth2 -s 0 -w - not port 22" | "C:\Program Files\Wireshark\Wireshark.exe" -k -i -