You manage a real-time gaming application on Compute Engine with separate production and testing environments, each with its own Virtual Private Cloud (VPC) network. The frontend and backend servers of the application reside on distinct subnets within their respective VPCs. Suspecting intermittent malicious communication within the production frontend servers, you intend to capture network traffic for analysis. What's the recommended approach?