-
Notifications
You must be signed in to change notification settings - Fork 393
Closed
Labels
arkimeRelating to Malcolm's use of ArkimeRelating to Malcolm's use of ArkimecaptureRelating to pcap-capture containerRelating to pcap-capture containerdashboardsRelating to Malcolm's OpenSearch Dashboards interfaceRelating to Malcolm's OpenSearch Dashboards interfaceenhancementNew feature or requestNew feature or request
Milestone
Description
Malcolm's Packet Capture Statistics dashboards shows information from Zeek and Suricata about packet loss, numbers of packets, missed ACKs, etc.
A user has requested to add to that dashboard, if possible:
- Statistics from Arkime
capture- I don't know where this is stored or if it's available to us, but I imagine it must be somewhere as I think Arkime has a corresponding visualization in its stats page
Statistics from the NIC itself (/proc-level)netdev-json.shis already used by fluent-bit on hedgehog and in the ISO-installed version of Malcolm to send NIC-level capture information, we could probably integrate it into the capture container (?) as well, but we'd have to hook up the plumbing to get it sent into the log pipeline which can be a bit of a trick (in Docker mode, at least) due to thenetwork: hostmode on the capture container. Probably need to make it just output to a file or something and have filebeat pick it up.- NOTE: moving this second part to another issue to track separately
Metadata
Metadata
Assignees
Labels
arkimeRelating to Malcolm's use of ArkimeRelating to Malcolm's use of ArkimecaptureRelating to pcap-capture containerRelating to pcap-capture containerdashboardsRelating to Malcolm's OpenSearch Dashboards interfaceRelating to Malcolm's OpenSearch Dashboards interfaceenhancementNew feature or requestNew feature or request
Type
Projects
Status
Released