Anyone have a good link on Sniffer AP mode?
Configure AP Sniffer mode as describe in the previous link.
The "Server IP address" is the address of the host where Wireshark is installed.
The WLC will sent UDP packets (with source port 5555) to the Wireshark host (with destination port 5000).
In Wireshark, follow the UDP stream and then decode UDP destination 5000 as "AIROPEEK" transport protocol.
You should now be able the see the frames captured by the AP on the selected channel.