Skip to content
Discussion options

You must be logged in to vote

Unless you're using role-based access control with Keycloak in Malcolm, your user does have admin access: it's just that Malcolm manages user accounts at a higher level than Arkime, which is why some of the user-management stuff in Arkime is not available in Malcolm (in other words, you manage user accounts at the Malcolm level, not the arkime level).

As far as the deleting of data in Malcolm goes, here are some options.

Automatic storage management

Malcolm can be configured to make sure you don't run out of disk space, see Managing Disk Usage.

To delete everything (wipe Malcolm sessions and PCAP back to a clean state)

./scripts/wipe

To delete indexes (i.e., sessions)

  1. Go into Dashboards
  2. C…

Replies: 8 comments 4 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
1 reply
@Anadema
Comment options

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
2 replies
@Anadema
Comment options

@mmguero
Comment options

Answer selected by mmguero
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
1 reply
@Anadema
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
upload Relating to PCAP and/or Zeek log ingestion opensearch Relating to Malcolm's use of OpenSearch
2 participants