From github.com
enhance support for syslog ingestion · Issue #354 · cisagov/Malcolm
1 1
Malcolm is now configurable to accept third-party syslogs directly. To describe the feature, here's copy/paste from the updated documentation: From the end-to-end configuration documentation: Shoul...
#ot #dhs #ics #inl #cisa #pcap #zeek #cyber #arkime #netbox
3h ago
From github.com
normalize winlogbeats with fluent bit winlog/winevtlog · Issue #356 · cisagov/Malcolm
1 1
@mmguero cloned issue idaholab/Malcolm#604 on 2024-10-29: The documentation describes setting up Beats to forward to Malcolm. We need to do the following: verify the documentation that it's (still?...
#ot #dhs #ics #inl #cisa #pcap #zeek #cyber #arkime #netbox
3h ago
From github.com
extracted_files_http_server.py not working with some filenames · Issue #524 · cisagov/Malcolm
1 1
the extracted_files_http_server.py used to provide the user interface for downloading zeek-carved files has an issue with some filenames, presumably with files with spaces in the name:
#ot #dhs #ics #inl #cisa #pcap #zeek #cyber #arkime #netbox
3h ago
From github.com
opensearch.keystore not created when running in Hedgehog profile · Issue #533 · cisagov/Malcolm
1 1
When running with the hedgehog profile, the opensearch.keystore file is not being created. This is technically okay, since it's not really needed: however, docker wants it to be present for the bin...
#ot #dhs #ics #inl #cisa #pcap #zeek #cyber #arkime #netbox
3h ago
From github.com
port numbers should not be shown with commas in Dashboards · Issue #540 · cisagov/Malcolm
1 1
General practice is not to include commas in port numbers (e.g., 51200 vs. 51,200). Dashboards management allows this to be configured: dashboard management > index patterns > arkime_sessions3* > s...
#ot #dhs #ics #inl #cisa #pcap #zeek #cyber #arkime #netbox
3h ago
From github.com
ensure all conn.log entries are tagged "ics" for OT protocols · Issue #541 · cisagov/Malcolm
1 1
We need to make sure that all conn.log entries get tagged with ics when an ICS protocol is detected. This is maybe already supposed to be handled but I don't see it is being done in every case. I w...
#ot #dhs #ics #inl #cisa #pcap #zeek #cyber #arkime #netbox
3h ago
From github.com
add navigation pane to non-network dashboards · Issue #543 · cisagov/Malcolm
1 1
The non-network log dashboards (e.g., third party logs, temperature, windows event logs, etc.) don't have the navigation pane on them, so it makes them more difficult to get back "home" from them. ...
#ot #dhs #ics #inl #cisa #pcap #zeek #cyber #arkime #netbox
3h ago
From github.com
URL pivot links from dashboards to arkime · Issue #551 · cisagov/Malcolm
1 1
I've got the ability now to make values in OpenSearch Dashboards tables URLs, which can be used to pivot from Dashboards to Arkime. At the moment, this will only work for OpenSearch Dashboards-base...
#ot #dhs #ics #inl #cisa #pcap #zeek #cyber #arkime #netbox
3h ago