of course it's possible. isp's require equipment like this to troubleshoot problems and detect/isolate denial of service attacks.
i used to work at an isp and built two sniffers like that that were used on a per-incident basis to watch traffic going to certain places (usually all traffic to and from a particular colocated server). in my case the devices weren't anything more than openbsd servers with tcpdump, snort, and other pcap utilities, but at larger isp's they would use something more proprietary to handle larger amounts of traffic. i'm sure if we had a good reason to we could have just left them on all the time and used something like snort or another deep packet inspector to trigger alerts on certain traffic.
i used to work at an isp and built two sniffers like that that were used on a per-incident basis to watch traffic going to certain places (usually all traffic to and from a particular colocated server). in my case the devices weren't anything more than openbsd servers with tcpdump, snort, and other pcap utilities, but at larger isp's they would use something more proprietary to handle larger amounts of traffic. i'm sure if we had a good reason to we could have just left them on all the time and used something like snort or another deep packet inspector to trigger alerts on certain traffic.