1 | initial version |
It looks like there is a bug in the code that changes the temporary coloring rules when you right-click and do "colorize with filter". When you repeat your steps, the filter of the previously created coloring rule gets updated instead of the new one. Could you file a bug report on https://bugs.wireshark.org with a reference to this question?
BTW it does not matter which field you do this for, I tried with the ip.id field and the behavior is the same.