Let’s say you want to capture packets for specific port 22, then you can execute the below command by specifying port number 22 as shown below.
$ tcpdump -i eth0 port 22
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth0, link-type EN10MB (Ethernet), capture size 65535 bytes
10:37:49.056927 IP > Flags [P.], seq 3364204694:3364204890, ack 4193655445, win 20904, length 196