New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
a few issues with pcap-over-ip #2573
Comments
So on a M1 mac everything seems to work fine.
|
Thanks Andy. I believe since the source interface was as for 3, my question is when does Arkime decides when to consider a session "finished" when receiving the pcap file over IP? is it when the underlying pcap-over-ip TCP session finishes, or the last byte of the pcap file that's transferred over TCP? |
|
cool got it. thanks mate :) |
So #2576 should hopefully fix the issue |
5.0.0-rc2 has this fix |
Describe the bug
I've been trying to use Arkime in a container to receive pcap-over-ip from polarproxy (amongst other sources) and I've observed a few things:
bpf=
option is set, I could not receive any packets. in my case, the option was set topbf=not port 9200
tcpdump
andtshark
) since by default they create pcaps with little-endian timestamps. I had to write my own makeshift packet capture that supports big-endian.tcpSaveTimeout
and essentially saves the session after 400 seconds. I tested this by lowering that number and sure enough the sessions showed up quicker.Elasticsearch version:
tested with opensearch 2.x and ES 8.x
Arkime/Moloch version:
tested with 4.6.0 and 5.0.0rc1
OS name and version:
Ubuntu 22.04 docker base image
How was Arkime/Moloch built/installed: (rpm, deb, easybutton, ...)
deb package on a container
Provide logs, stack traces and steps to reproduce:
the docker compose to set up the entire stack is here, with all the configuration items for ES, Polarproxy and Arkime:
https://github.com/mosajjal/aio-gw
The text was updated successfully, but these errors were encountered: