Skip to content
Discussion options

You must be logged in to vote

Malcolm is a tool suite that includes both Zeek and Arkime, and has some customizations to both that makes it possible to see Zeek logs in Arkime. But if you've just installed Zeek on one endpoint, and Arkime on another, and those aren't part of a Malcolm installation, then Malcolm isn't really going to be able to help you.

If you're interested in installing Malcolm, here are some resources I can point you to (most of which are also gathered in the wiki):

Malcolm isn't…

Replies: 2 comments 2 replies

Comment options

You must be logged in to vote
2 replies
@Satsubu
Comment options

@mmguero
Comment options

Answer selected by mmguero
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants