Snort is flexible. You might use it as a real-time traffic analysis tool, or as a sniffer to record and log packets. The real value of Snort though is the intrusion detection capability. Rules in Snort are powerful, flexible, and can be customized any way you need. There are hundreds of rules devised by experts if you don't know or care how to learn to craft them. Snort allows detection of vulnerabilities, exploits, or other conditions. Snort has IPv6 support.
Snort supports logging to MySQL, Oracle, Microsoft SQL Server, and ODBC databases on the Windows version. All the capabilities come for free, other than 0-day real-time updates of the rules database. Even real-time updates of the VRT are affordable by comparison with other options: for businesses a year subscription is $499 per sensor for 1-5 sensors.