I would suggest setting up a snort session. www.snort.org

This will allow you to capture all/(or any that you choose) packets traversing your network.

Can't help with the zonealarm side, I use tiny personal software's firewall which logs all traffic on each machine per rules I create.

cheers