"write-file" is a hidden option, you have to type it in full. File format is PCAP, you can directly open it in Wireshark after downloading. You may also notice that locally-generated packets may or may not be captured depending on PIC used.
With transit traffic, you have 2 options:
1/ port-mirroring into a different port with connected laptop/analyzer/PC with Wireshark. Port-mirroring also captures locally-originated and locally-terminated traffic.
2/ _only_ on Jseries or branch SRX: "packet-capture" feature