Wireshark
Start analysis with Statistics. Capture File properties for a summary of traffic. Protocol Hierarchy for traffic by layers and stats. Conversations provides insight into IPs and Ports. Large file transfers. And small mapping activity can be found here.
Analyze TCP Session can show an entire conversation.
Find a Packet by String and Packet Bytes. Then Follow the Stream for the whole conversation.
Use Profiles to customize your view of Wireshark. If you do common tasks and focus on certain items, create views and switch between them to speed analysis.