Você pode querer usar tshark para isso em vez de tcpdump. Tshark usa o mesmo formato pcap, mas tem opções muito melhores para registro contínuo.
Uma opção é o modo de buffer de toque tshark .
-b Cause TShark to run in "multiple files" mode. In "multiple files" mode, TShark will write to several capture files. When the first capture file fills up, TShark will switch writing to the next file and so on.
The created filenames are based on the filename given with the -w option, the number of the file and on the creation date and time, e.g. outfile_00001_20050604120117.pcap, outfile_00002_20050604120523.pcap, ...