Skip to content

How to Read PCAPs and Generate Logs with Zeek and Suricata in Hedgehog #343

Closed Answered by mmguero
MLIndeed asked this question in Q&A
Discussion options

You must be logged in to vote

I'm still not coming through clearly: the Malcolm profile is the only profile that processes uploaded PCAP. The way you're configuring it (with the hedgehog run profile) is only for live traffic capture.

If you want to process PCAP files by uploading them, you need to configure Malcolm in its full Malcolm run profile.

Also, you should never have to modify the docker-compose file directly to turn on and off services. You don't understand what the services are doing: for example, by disabling the filebeat service, Zeek logs generated from the PCAP files will never make their way into the parsing pipeline.

Blow away your Malcolm installation, start over, and walk through the configuration wi…

Replies: 2 comments 6 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
6 replies
@mmguero
Comment options

@MLIndeed
Comment options

@mmguero
Comment options

Answer selected by mmguero
@MLIndeed
Comment options

@mmguero
Comment options

@MLIndeed
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
upload Relating to PCAP and/or Zeek log ingestion
2 participants