You should create a new profile in Wireshark with all protocols enabled. The user can then switch back to his previous profile, and you run tshark with the "-C profilename" option to use the all-protocols-enabled profile