I use it all the time. It's very easy to use. Just plug your wireshark host into the destination SPAN port and go to Capture > Start. That will start capturing all ports spanned from the source. If you want to do filtering of these packets as the capture is running, go to Capture > Options and define a capture filter. For example, to filter on all HTTP traffic, use the filter "tcp port 80".