Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
dashboards-helper container's use of curl fails internal container name resolution when host has invalid DNS settings, prevents Malcolm initialization (idaholab/Malcolm#499)
Netbox service templates not populating (idaholab/Malcolm#522)
kubernetes manifest for netbox refers to netbox-netmap-json configmap which no longer exists (idaholab/Malcolm#540)
don't try to expose the OpenSearch port 9200 in docker-compose.yml when the database mode is not opensearch-local
improved the liveness check for the offline Zeek container so that it returns "healthy" if the intel thread feeds are still pulling before the monitoring processes start up
Malcolm v24.08.0 contains minor improvements, some component version updates, and bug fixes.
https://github.com/cisagov/Malcolm/compare/v24.07.0...v24.08.0
netbox
tag to any logs that are passed into thenetbox_enrich.rb
script in the Logstash enrichment pipelinedocker-compose.yml
when the database mode is notopensearch-local