-Coption. This approach is fine, but it means that any sort of basic trend analysis will require a little bit of automated help. If rotation is done on a time basis, a simple
ls -lwill show when traffic peaked or bottomed out. To this end, I authored a patch which was accepted upstream.
E.g. Dump 10 minutes worth of data in 60 second files:
tcpdump -G 60 -w timedump -s 0 -C 10