Closed mmguero closed 3 months ago
Another option: allowing arkime to use a specified alias to query rather than the arkime_sessions3*
value.
Ideally it would be nice if Arkime could have a configurable param to accept multiple indexes or use an Elastic alias to combine the indexes.
Kassio filed a ticket with those Arkime folks which was subsequently closed. This may be an Arkime limitation. https://github.com/arkime/arkime/issues/2555
See the PR work in progress for Arkime: arkime/arkime#2705
With arkime/arkime#2705 merged this will make it into this Malcolm release (either via a small patch for v5.0.1 or in v5.0.2 once that's released).
Now with #313, we can write the suricata and zeek logs to another index pattern. However, those logs aren't queryable in Arkime.
Arkime from what I can tell hard-codes the
arkime_sessions3-*
index pattern throughout the code. However, it maybe be possible to specify multiple index patterns to query:We are going to look into how feasible it would be to 1) specify via an arkime config.ini setting another index pattern to query and 2) pick up and use that index pattern and include it in the existing arkime queries. This change would need to be made to the upstream arkime repo and accepted there as a PR to be feasible for use in Malcolm, we're not interested in maintaining a downstream arkime fork.