Wireshark starts to break down at a certain point. When that happens, I've found scapy (Python pcap parser) very useful. Once that breaks down, a good option reading the hex directly in C.
Once that breaks down... Well, there be dragons.
tshark -i eth0 -Y ip.addr==8.8.8.8
Instead of having to remember tcpdump's own fiddly syntax. Given that most of my protocol debugging work is done inside Wireshark, I'm much more fluent in that filter language.
Note that the above snippet is a display filter, so it's capturing all the packets on the wire, doing a full dissection, and then running them through a filter before printing them; if you're trying to capture on a saturated 1G link you might need to fall back to the capture filters which are simpler and faster (and I believe also use tcpdump's syntax).
Sometimes "ease of use" is really just "what I'm used to". (Not saying Wireshark isn't more expressive or more powerful...it probably is. But, I usually have a very basic use case, and tcpdump can do it with a couple of flags and an address or port.)
Its creator was one of the guys behind wireshark. They're pitching sysdig as strace + tcpdump + htop + iftop + lsof + ...awesome sauce.
They have csysdig which is similar to tshark