You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
After installation of a Malcolm instance via ISO-Image I started capturing local traffic. All the traffic is captured, analyzed and ingested into Opensearch as intended. But after rebooting the Malcolm-Stack or the whole machine any captured PCAP-Data gets reingested and Zeek-Logs are doubled in Opensearch. Anytime the container is restarted, the files are ingested again.
I guess whatever component is watching for new PCAPs to analyze should somehow persist already processed files so that even after container-reboot the data won't get ingested again.
The text was updated successfully, but these errors were encountered:
Thanks for logging the issue. While there are some docker-compose values to explicitly prevent that from happening (EXTRACTED_FILE_IGNORE_EXISTING and PCAP_PIPELINE_IGNORE_PREEXISTING) which you might be able to use as a stopgap in the meantime while I investigate the issue, it still should not be duplicating your data during processing. I'll look at this.
After installation of a Malcolm instance via ISO-Image I started capturing local traffic. All the traffic is captured, analyzed and ingested into Opensearch as intended. But after rebooting the Malcolm-Stack or the whole machine any captured PCAP-Data gets reingested and Zeek-Logs are doubled in Opensearch. Anytime the container is restarted, the files are ingested again.
I guess whatever component is watching for new PCAPs to analyze should somehow persist already processed files so that even after container-reboot the data won't get ingested again.
The text was updated successfully, but these errors were encountered: