It turns out when you take a pakcet capture from a controller it is *not* ERM encapsulated. It is GRE encapsulated. The capture filter I'm not using successfully is "ip proto 0x2f". I'm sure it could be refined to a particular source address or other parameters as well, but this is the only GRE traffic on my monitoring endpoint so this filter is sufficient.
I'm not sure why this isn't documented anywhere currently. The TAC engineer I spoke to is going to document it internally as well as here on AirHeads, but I thought I would post it too in case it helps someone else.