I regularly apply a color rule for each A > B conversation, so i can see which host is the source for each packet. This is really useful when dealing with two party communication ( A <> B ) but recently i found it pretty much indispensable while dealing with a server in the middle of a three-way conversation ( A <> B <> C ). It would make my life a lot easier if there was a way of creating a macro for assigning coloring rules like this, I cant imagine you can create a macro of actions taken in the conversation list so maybe it could work instead by selecting a host, tagging its ip.src as a rule and applying a color. This may not even be possible, but its something i do so regularly it would be awesome if i could speed the process up. Is this possible within wireshark? asked 22 Jul '14, 09:10 AlexH |