ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-users: [Wireshark-users] Wireshark V1.4 Display Filter Syntax Highlighting

From: "Keith French" <keithfrench@xxxxxxxxxxxxx>
Date: Tue, 2 Nov 2010 14:43:05 -0000
I've noticed that apart from the normal green or red background colours used for display filter syntax highlighting, a new colour of amber or yellow has been introduced. I am guessing this cam in in V1.4.0 or 1.4.1. What is its significance?

If I enter a filter such as:-

rtp.p_type eq 97   it is green

If I use:-

rtp.p_type ne 97   it is amber

Is this just a warning in case you have used the classic mistake of:-

ip.addr ne 10.10.10.10