Ask Your Question

Revision history [back]

click to hide/show revision 1
initial version

It looks like there is a bug in the code that changes the temporary coloring rules when you right-click and do "colorize with filter". When you repeat your steps, the filter of the previously created coloring rule gets updated instead of the new one. Could you file a bug report on https://bugs.wireshark.org with a reference to this question?

BTW it does not matter which field you do this for, I tried with the ip.id field and the behavior is the same.