Skip to content

Why does live-captured PCAP have to be periodically rolled for analysis by Arkime? #328

Closed Answered by mmguero
mmguero asked this question in Q&A
Discussion options

You must be logged in to vote

When monitoring traffic on a local network interface, the reason that Arkime can't capture "on demand" in a Malcolm standalone installation is due to its necessity to communicate with the internal OpenSearch instance and at the same time listen on the physical interface provided to it in "host" network mode. I'm not aware of a way to configure it to be able to do both of those things using Docker.

However, there are a few options for running live Arkime capture:

Replies: 1 comment

Comment options

mmguero
Aug 9, 2024
Maintainer Author

You must be logged in to vote
0 replies
Answer selected by mmguero
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
1 participant