-
Notifications
You must be signed in to change notification settings - Fork 356
cisagov Malcolm Discussions
Sort by:
Latest activity
Categories, most helpful, and community links
Categories
Community links
Discussions
-
You must be logged in to vote 🌟 -
You must be logged in to vote ❓ -
You must be logged in to vote 🌟 -
You must be logged in to vote 💭 -
You must be logged in to vote ❓ Questions about ENV_PCAP_FILTER
captureRelating to pcap-capture container -
You must be logged in to vote ❓ Regarding Performance Monitoring
elasticRelated to issue with external ElasticSearch/Kibana output logstashRelating to Malcolm's use of Logstash opensearchRelating to Malcolm's use of OpenSearch performanceRelated to speed/performance -
You must be logged in to vote ❓ File extraction configuration conflicts with zeek default extraction
bugSomething isn't working -
You must be logged in to vote ❓ -
You must be logged in to vote 😮 -
You must be logged in to vote 😮 -
You must be logged in to vote 😥 Unexpected behavior indexes
elasticRelated to issue with external ElasticSearch/Kibana output -
You must be logged in to vote 🌟 -
You must be logged in to vote ❓ Forward remote Zeek logs to Malcolm for analysis in Dashboards and Arkime
zeekRelating to Malcolm's use of Zeek logstashRelating to Malcolm's use of Logstash externalDepends on a bug or feature external to this project -
You must be logged in to vote 😥 After restarting Malcolm, zeek did not start
zeekRelating to Malcolm's use of Zeek -
You must be logged in to vote 🌟 -
You must be logged in to vote ❓ Permission Error Running suricata-update list-sources in Suricata Container
suricataRelating to Malcolm's use of Suricata -
You must be logged in to vote 😥 -
You must be logged in to vote ❓ -
You must be logged in to vote ❓ -
You must be logged in to vote 😥 Arkime exporting 0 byte PCAP
arkimeRelating to Malcolm's use of Arkime -
You must be logged in to vote 🌟 -
You must be logged in to vote 😥 netbox not starting
netboxRelated to Malcolm's use of NetBox -
You must be logged in to vote ❓ Zeek/Suricata Alerts without matching PCAP
arkimeRelating to Malcolm's use of Arkime -
You must be logged in to vote 😥 Filebeat keeps restarting
cloudRelating to deployment of Malcolm in the cloud and/or with Kubernetes