Arkime viewer not rolling pcaps #484
Labels
arkime
Relating to Malcolm's use of Arkime
bug
Something isn't working
capture
Relating to pcap-capture container
regression
It worked at one point...
Milestone
Describe the bug
We are running a full Malcolm setup with docker compose using the
malcolm
profile that monitors a local network interface withnetsniff-ng
. As per the docs for a low resources environment,SURICATA_LIVE_CAPTURE
/ZEEK_LIVE_CAPTURE
are set tofalse
andSURICATA_ROTATED_PCAP
/ZEEK_ROTATED_PCAP
are set totrue
.Pcaps are filling up the drive they are on, even with
MANAGE_PCAP_FILES
set toTrue
. Everything showsFalse
underLocked
in the arkimefiles
tab.Expected behavior
The
arkime
container should delete pcaps once the disk usage has surpassed the designated amount of free space.Malcolm Version:
How are you running Malcolm?
Additional context
Upon further investigation, I found an old issue and this commit that referenced the same problem. In the
arkime
container, thepcapDir
was set to/data/pcap/arkime-live
by the docker entrypoint. After changing thepcapDir
back toprocessed
in theconfig.ini
and restarting the viewer process, it correctly removed pcaps to make space.I'm assuming the issue lies here, but I'm not very familiar with Malcolm. We are not using arkime live capture so I wonder if that replacement should only be applied when that is the case?
The text was updated successfully, but these errors were encountered: