A powerful, easily deployable network traffic analysis tool suite

Quick Start



Supported Protocols




Hedgehog Linux

Contribution Guide

OpenSearch index management

Malcolm releases prior to v6.2.0 used environment variables to configure OpenSearch Index State Management policies.

Since then, OpenSearch Dashboards has developed and released plugins with UIs for Index State Management and Snapshot Management. Because these plugins provide a more comprehensive and user-friendly interface for these features, the old environment variable-based configuration code has been removed from Malcolm, with a few exceptions. See Managing disk usage for more information.

Using ILM/ISM with Arkime

Arkime allows setting index management policies with its sessions and history indices. The Malcolm environment variables for configuring this behavior are set in arkime.env. These variables can be used for both OpenSearch and Elasticsearch instances (OpenSearch Index State Management (ISM) and Elasticsearch Index Lifecycle Management (ILM), respectively).