Without any options set, TShark will work much like tcpdump. TShark is able to detect, read and write the same capture files that are supported by Wireshark.
Display all the traffic in CLI:
sudo tshark -i eth1
To write all the traffic to a file in txt format from a network interface:
sudo tshark -i eth1 > /home/ftp/speedy/tshark.txt
The following example displays only IP packets that are issued by or in destination to the IP address 192.168.0.1
sudo tshark -i eth1 -R "ip.addr == 192.168.0.1" > /home/ftp/speedy/tshark.txt
In the following example, only IP packets that are coming from or going to UDP port 1812 are captured.
sudo tshark -i eth1 -f "udp port 1812" > /home/ftp/speedy/tshark.txt
All the available command lines are found here.