A powerful, easily deployable network traffic analysis tool suite for network security monitoring
OpenSearch Dashboards is an open-source fork of Kibana, which is no longer open-source software.
Visualizations and dashboards can be easily created in OpenSearch Dashboards using its drag-and-drop WYSIWIG tools. Assuming users have created a new dashboard to package with Malcolm, the dashboard and its visualization components can be exported using the following steps:
/dashboards/app/dashboards#/view/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
the ID would be xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
)./dashboards./dashboards/
directory with the following command:
export DASHID=xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx && \
docker compose exec dashboards curl -XGET \
"http://localhost:5601/dashboards/api/opensearch-dashboards/dashboards/export?dashboard=$DASHID" > \
./dashboards/dashboards/$DASHID.json
arkime_sessions3-*
index template rather than including it in imported dashboards, so edit the xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx.json
that was generated, carefully locating and removing the section with the id
of arkime_sessions3-*
and the type
of index-pattern
(including the comma preceding it):
,
{
"id": "arkime_sessions3-*",
"type": "index-pattern",
"namespaces": [
"default"
],
"updated_at": "2021-12-13T18:21:42.973Z",
"version": "Wzk3MSwxXQ==",
…
"references": [],
"migrationVersion": {
"index-pattern": "7.6.0"
}
}
arkime_sessions3-*
with MALCOLM_NETWORK_INDEX_PATTERN_REPLACER
and malcolm_beats_*
with MALCOLM_OTHER_INDEX_PATTERN_REPLACER
. These replacers are used to allow customizing indexes for logs written to OpenSearch or Elasticsearch../dashboards/dashboards/
directory or by rebuilding the dashboards-helper
image. Dashboards are imported the first time Malcolm starts up.The dashboards.Dockerfile installs the OpenSearch Dashboards plugins used by Malcolm (search for opensearch-dashboards-plugin install
in that file). Additional Dashboards plugins could be installed by modifying this Dockerfile and rebuilding the dashboards
image.