Packet or frame slicing our captures can be a great way to hide information in trace files if done correctly. However, you have to really understand the reason for the captures in the first place. For example, often times application performance issues leave many clues at layer 4 (specifically TCP). What happens when you 'hard" slice a trace file and now cannot follow the TCP sequence numbers because the incorrect frame size value is written in the pcap file?
Other times you may need to see the specific application call (SQL/Oracle) to actually fix the problem but you no longer have that data because you've sliced it away.