To analyze traffic remotely over ssh:

ssh [email protected] sudo tcpdump -U -s0 -i pflog0 -w -| wireshark -k -i -

In case need an specific port:

ssh [email protected] sudo tcpdump -U -s0 -i pflog0 -w - 'port 5984' | wireshark -k -i -

To ignore trafic from ssh:

ssh [email protected] sudo tcpdump -U -s0 -i pflog0 -w - 'not port 22' | wireshark -k -i -