When running something like this on a large scale to capture all traffic going across a network, you'd typically use a "network packet broker" (cf. Google) that sends a copy of all traffic to the machine(s) running this software.
Your hypothetical application server would not even be aware that this was taking place.
Your hypothetical application server would not even be aware that this was taking place.