So assuming that you have a TN5250 session over Telnet over TLS over IP, you'll probably see an exchange of TLS packets between server and client. _But_ if you happen to have access to the encryption keys used for the TLS connection you could enter these into Wireshark allowing decryption. However this depends heavily on the encryption method used, and possibly key material provided by the server of client. Since this is very implementation specific there's no general advise to give about this.