Wireshark mailing list archives

Re: Removing existing coloring filter for Wireshark 2.4.0 for Mac OSX


From: "Maynard, Chris" <Christopher.Maynard () IGT com>
Date: Thu, 17 Aug 2017 20:01:48 +0000

I would refer you to my answer to this question: 
https://ask.wireshark.org/questions/63045/impossible-to-edit-the-color-rule

Basically, delete your colorfilters file(s) from your personal configuration directory, then copy over the default 
colorfilters file from the Wireshark installation directory to your personal configuration directory.  You should be 
able to edit or import coloring rules after that.

- Chris

From: Wireshark-dev [mailto:wireshark-dev-bounces () wireshark org] On Behalf Of puppyhawk () gmail com
Sent: Wednesday, August 16, 2017 3:57 AM
To: wireshark-dev () wireshark org
Subject: [Wireshark-dev] Removing existing coloring filter for Wireshark 2.4.0 for Mac OSX

Hi all,

I'm trying to remove existing coloring rule from Wireshark 2.4.0 for Mac OSX in order to import a new coloring filter 
file.
My Macbook Pro is running 10.11.6, El Capitan.
Wireshark remember its preexisting coloring filter on fresh install even after I removed Wireshark app from 
/Application, and followed the uninstall instructions described in ReadMe.rtf.
"colorfilter" must be the filename though it did not help to remove the file to force Wiresahrk forget the old coloring 
rule.

I need to import a new coloring filter which is compatible for 2.4.0 while the old preexisting rule is not.
When I tried to remove all lines from GUI then clicked OK, I see "Wireshark doesn't recognize one or more of your 
colouring rules. They have been disabled." error even though there is no rule defined...

What should I do to import the new rule file and remove old unsupported syntax rule?

Thanks in advance.

Regards,
Hide
puppyhawk () gmail com<mailto:puppyhawk () gmail com>
CONFIDENTIALITY NOTICE: This message is the property of International Game Technology PLC and/or its subsidiaries and 
may contain proprietary, confidential or trade secret information.  This message is intended solely for the use of the 
addressee.  If you are not the intended recipient and have received this message in error, please delete this message 
from your system. Any unauthorized reading, distribution, copying, or other use of this message or its attachments is 
strictly prohibited.
___________________________________________________________________________
Sent via:    Wireshark-dev mailing list <wireshark-dev () wireshark org>
Archives:    https://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev
             mailto:wireshark-dev-request () wireshark org?subject=unsubscribe

Current thread: