Thanks very much.
-----Original Message----- 
From: Jeff Morriss
Sent: Tuesday, November 02, 2010 3:00 PM
To: Community support list for Wireshark
Subject: Re: [Wireshark-users] Wireshark V1.4 Display Filter 
SyntaxHighlighting
Keith French wrote:
I've noticed that apart from the normal green or red background colours 
used for display filter syntax highlighting, a new colour of amber or 
yellow has been introduced. I am guessing this cam in in V1.4.0 or 1.4.1. 
What is its significance?
Actually it was there in 1.2 too.
If I enter a filter such as:-
rtp.p_type eq 97   it is green
If I use:-
rtp.p_type ne 97   it is amber
Is this just a warning in case you have used the classic mistake of:-
ip.addr ne 10.10.10.10
Yes.  There should be a warning explaining the color in the...  I guess
it's a status bar in the lower-left corner (the same place that the
field explanation and the field's dfilter are shown when you select a
protocol item).
___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
            mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe