Shark SE400 User's Guide Page 185

  • Download
  • Add to my manuals
  • Print
  • Page
    / 228
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 184
Customizing Wireshark
176
The first match wins
More specific rules should usually be listed before more general rules. For example, if
you have a coloring rule for UDP before the one for DNS, the rule for DNS may not be
applied (DNS is typically carried over UDP and the UDP rule will match first).
You can create a new rule by clicking on the + button. You can delete one or more rules by clicking
the - button. The “copy” button will duplicate a rule.
You can edit a rule by double-clicking on its name or filter. In Figure 10.1, “The “Coloring Rules”
dialog box” the name of the rule “Checksum Errors” is being edited. Clicking on the Foreground and
Background buttons will open a color chooser (Figure 10.2, “A color chooser”) for the foreground
(text) and background colors respectively.
Figure 10.2. A color chooser
The color chooser appearance depends on your operating system. The OS X color picker is shown.
Select the color you desire for the selected packets and click OK.
Figure 10.3, “Using color filters with Wireshark” shows an example of several color filters being used
in Wireshark. Note that the frame detail shows that the “Bad TCP” rule rule was applied, along with
the matching filter.
Page view 184
1 2 ... 180 181 182 183 184 185 186 187 188 189 190 ... 227 228

Comments to this Manuals

No comments