Skip to content

Arkime exporting 0 byte PCAP #594

Closed Answered by mmguero
riley611 asked this question in Troubleshooting
Feb 20, 2025 · 1 comments · 12 replies
Discussion options

You must be logged in to vote

It could be one of a few things happening here:

  1. Malcolm is unable to contact the Hedgehog on port 8005/tcp, because either it's being blocked by the hedgehog's software firewall (which is what MALCOLM_REQUEST_ACL should have taken care of) or some other firewall or something else you have in between. There are a few things we could do to check this:

    • on Hedgehog, as root, run ufw status, you should see a rule for port 8005/tcp for your Malcolm's IP address
    • on Malcolm run portping #.#.#.# 8005 where #.#.#.# is the Hedgehog IP address, it should report OPEN
  2. Hedgehog by default is using zstd compression on PCAPs, and if you're requesting payloads that are very recent it might not have t…

Replies: 1 comment 12 replies

Comment options

You must be logged in to vote
12 replies
@riley611
Comment options

@mmguero
Comment options

@riley611
Comment options

@mmguero
Comment options

Answer selected by mmguero
@riley611
Comment options

@riley611
Comment options

@mmguero
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
arkime Relating to Malcolm's use of Arkime
2 participants