Comments (1)
There are a couple of settings that can be tweaked with regards to storage space utilized:
- OpenSearch index storage: during the configuration questions (
./install.py --configure
) you're askedDelete the oldest indices when the database exceeds a certain size?
. If you answery
to this question, it will prompt you for a size (Enter index threshold (e.g., 250GB, 1TB, 60%, etc.)
) andDetermine oldest indices by name (instead of creation time)?
. This last question, if answeredy
, will treat the indexes with the earliest data as oldest, where an
will treat the indexes with the most recently inserted data. If the data you're analyzing is live, then there's not a meaningful difference. Malcolm's OpenSearch indexes are organized by day, so you'd of course need to have enough disk space for at least a couple of days' worth of indexes. But beyond that, when your opensearch indexes go beyond the threshold specified, the oldest indexes will be deleted. You can also check out the documentation on index management. - PCAP storage: Also during the
./install.py --configure
questions, you'll be promptedShould Arkime delete PCAP files based on available storage (see https://arkime.com/faq#pcap-deletion)?
You can review that link for more information there, but answeringy
to this question will allow Arkime's background processes to delete old PCAP files as the PCAP fills up disk space. However, by default the value in Arkime'sconfig.ini
offreeSpaceG=10%
will reserve 10% of the total disk as free before deleting PCAPs. If you wish to change this value, then you'll need to make changes to your localarkime/etc/config.ini
file (depending on how you installed Malcolm you may need to download this from GitHub or from a git cloned working repository), ensure it's being bind-mounted in your docker-compose file like this and then restart Malcolm. - Zeek and Suricata log and artifact storage: In Malcolm's docker-compose files, there are values for how long before Zeek and Suricata logs are cleaned up . The settings for carving and preserving carved files from traffic may also be of interest.
I think that about covers it.
from malcolm.
Related Issues (20)
- Logs are being spammed with Suricata warnings pertaining to duplicate rules HOT 4
- logstash hanging on startup HOT 2
- Local Opensearch Instance Unreachable HOT 3
- Dashboards not loading HOT 3
- how to activate SFTP/SSH HOT 11
- Idea: Terminate `./script/start` once Malcolm has started properly. HOT 2
- zeek detecting SFTP through script and not SFTP through applications like WinSCP and FileZilla HOT 2
- Unable to upload and analyze file HOT 1
- Error in /etc/supervisord.conf prevents wise service from starting up and arkime container unhealthy HOT 4
- install.py bug HOT 2
- install.py can create .env files 0:0 ownership instead of unprivileged user ownership HOT 10
- Name attributes for page sections in documentation are broken HOT 2
- Netbox disabled HOT 1
- Start Script Changing Permissions HOT 2
- iso installation failed HOT 1
- Whether the suricata rule is triggered HOT 2
- Arkime Session Dropdown Not Displaying PCAP Data HOT 2
- Unable to get iso from vagrant build script HOT 2
- support PCAP files with 802.11 packet structure HOT 2
- PCAP File with no `-` in pcapng Fails to Upload HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from malcolm.