Hi.
Often, when I have a packet with alot of elements, it's a bit hard to
find the element matching the display filter. And when using a
complex filter it would be nice to know why each packet matches.
Does wireshark have any functionality like this? I know we have "Find
Packet", but this does not display the matching element in the packet.
I see two possible enhancements here:
1. Colorize the element matching the filter, like the expert info.
2. Implement a function to expand the tree to the element matching the
display filter in this packet, and highlight this.
Anyone with a deeper knowledge about the display filter engine who can
point in a direction how to implement such a feature?
--
Stig Bjørlykke