Malcolm v6.4.1 is a minor release containing a few bug fixes, component version updates and other improvements.
- Bug fixes
- Zeek log files that have been renamed and are in the process of moving not caught correctly by Logstash (idaholab#121)
- Hedgehog Arkime viewer node should use TLS (idaholab#122)
- Recent changes to Elastic Common Schema needed adjustment (map
number
data type tolong
)
- Component version updates
- Improvements
- On Hedgehog Linux, allow configuration of Arkime
capture
to use PCAP compression if desired - Changes to GitHub Docker image and ISO workflows, updating deprecated actions and features
- Create corresponding
net-map.json
/Host and Subnet Name Mapping items in NetBox on when applicable - Remove unnecessary
linux-headers-
package from Zeek Docker image
- On Hedgehog Linux, allow configuration of Arkime
Malcolm and Hedgehog Linux may be obtained by pulling or building the Docker images and/or building the ISO installer images as described in the documentation. Unofficial ISO installer images for Malcolm and Hedgehog Linux are not hosted on GitHub, but may be downloaded from https://malcolm.fyi/.