官术网_书友最值得收藏!

Colorization and coloring rules

Colorization of packets displayed in the Packet List pane can be an effective tool to identify and highlight packets of interest, especially the packets that contain or indicate some kind of error condition.

Wireshark has predefined coloring rules that are enabled by default and which can result in a kaleidoscope of colored packets in the Packet List pane. You can enable or disable the coloring rules by selecting Colorize Packet List from the View menu or by clicking on the Colorize Packet List icon in the icon bar if this becomes overwhelming.

You can also view, enable/disable, add, delete, reorder, and edit the coloring rules by selecting Coloring Rules from the View menu or by clicking on the Edit Coloring Rules icon in the icon bar. There is a Clear button that removes all the changes you may have made to the rules and restores them to default settings if needed.

A Coloring Rules window is depicted in the following screenshot:

Coloring rules employ display filter formats with specific values to identify packets that should be colored. The rules are compared to packets starting with the top rule and working down through the list. Only the first rule that matches a packet's condition is applied, so the ordering of the rules dictates which rule gets applied if more than one rule matches a packet. If you create or modify a rule, you have to check the ordering to make sure you get the desired behavior.

Clicking on a rule and then clicking on Edit allows you to modify the foreground and background colors for that rule, as well as change the filter string if desired.

You can also export/import coloring rules if you want to share them with others. Coloring rules are stored in a file called colorfilters in one of your personal configuration directories depending on the profile in use.

Packet colorization

You can also temporarily color a series of packets in a conversation by selecting one of the conversation packets, selecting Colorize Conversation from the View menu, and selecting a color from the adjoining menu, or by right-clicking on a packet, selecting Colorize Conversation from the menu, selecting one of the protocol-specific options, and then selecting the desired color. This colorization will disappear when the capture file is reloaded, or you can select Reset Coloring 1-10 from the View menu.

主站蜘蛛池模板: 石城县| 汾阳市| 玉田县| 桃园市| 台山市| 高清| 新昌县| 陇川县| 武清区| 松阳县| 广元市| 江达县| 曲松县| 陕西省| 陈巴尔虎旗| 微博| 岚皋县| 衡山县| 积石山| 安庆市| 临武县| 湖州市| 汝阳县| 高青县| 满洲里市| 巢湖市| 文登市| 宁海县| 耿马| 浠水县| 龙里县| 洛宁县| 莆田市| 灵寿县| 汶上县| 赤城县| 布拖县| 望城县| 卓资县| 泾阳县| 都兰县|