cisagov / Malcolm

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
https://cisagov.github.io/Malcolm/
Other
1.96k stars 328 forks source link

Arkime: Queries and Filters #431

Open mmguero opened 1 week ago

mmguero commented 1 week ago

@mmguero cloned issue idaholab/Malcolm#366 on 2024-01-15:

For what topic would you like to see training developed?

show how to write search queries and use the UI to apply filters in Arkime

What format would be best suited for this training?

a video

Is there existing Malcolm documentation that could be improved by including this topic?

Search Queries in Arkime and OpenSearch Dashboards