Skip to content
Discussion options

You must be logged in to vote

A couple of things to help you understand what's going on here:

There's nothing on hedgehog that "forwards pcap files to malcolm for analysis." Full PCAP remains at the point of capture, on the hedgehog sensor. What gets forwarded to Malcolm is metadata from one ore more of the three tools that are examining network traffic:

  • Zeek
  • Suricata
  • Arkime capture

However, Arkime capture is unique in that in addition to the summaries of network sessions it sends to Malcolm, it stores the PCAP locally and sends information to Malcolm about where to find each session in that PCAP file. When the user goes to the Arkime viewer's Session page on Malcolm and expands an arkime session record, Malcolm rea…

Replies: 1 comment 7 replies

Comment options

You must be logged in to vote
7 replies
@jakestre
Comment options

@mmguero
Comment options

@jakestre
Comment options

@mmguero
Comment options

@jakestre
Comment options

Answer selected by jakestre
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
sensor For issues dealing with the Hedgehog OS capture sensor
2 participants