ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-dev: [Wireshark-dev] Adding an optional expert field to colouring rules?

From: Martin Mathieson <martin.r.mathieson@xxxxxxxxxxxxxx>
Date: Tue, 6 Aug 2013 13:21:39 +0100
Hi,

I sometimes add colouring rules for some condition I am only interested in for a short time (i.e. its not worth adding expert info for to the relevant dissector).  Then, I want to quickly find the frames that match that condition.  I realise that I can use filtering rules such as:

frame.coloring_rule.name == "The Rule Name"

but it would be convenient to have a field where I could choose the severity of the expert item (including, as default, none).  Then, when a rule matches, expert info would be added (using the rule name), and I could quickly:
- see that the condition happened (if it causes the circle to change colour)
- see how many times it happened
- browse to instances from the expert info window

Would others find this feature useful?  Would it seem wrong to configure/generate expert info from 'Coloring Rules...' ?  The expert info item itself would be in the 'Frame' tree, rather than at the item for the display filters used in the rule filter _expression_.

Regards,
Martin