tcpdump -tnn -c 20000 -i eth0 | awk -F "." '{print $1"."$2"."$3"."$4}' | sort | uniq -c | sort -nr | awk ' $1 > 100 '
Pipe tcpdump output over a SSH connection:
ssh [USERNAME]@[IP ADDRESS] "tcpdump -s 0 -ni [INTERFACE] [FILTERS] -w - " > [FILEPATH]