home.social

#elasticsearch — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #elasticsearch, aggregated by home.social.

  1. CW: release notes for Malcolm v26.07.0, a network traffic analysis tool suite for network security monitoring

    Malcolm v26.07.0 adds IEC 60870-5-104 (IEC 104) protocol support using CERT.LV's Zeek plugin, including Logstash parsing, ECS normalization, Arkime fields, and a new OpenSearch Dashboards dashboard. This release also fixes three archive extraction and authentication security vulnerabilities; improves NetBox enrichment configuration; and addresses PostgreSQL major version upgrade, custom CA certificate for KeyCloak, container health check, privilege-drop signal chaining, and configuration script issues. Arkime, Zeek, Fluent Bit, Filebeat, Logstash, Supercronic, and Alpine-based images have been updated as well.

    If you are upgrading from an existing Malcolm installation, run ./scripts/status for Malcolm to migrate some settings prior to running ./scripts/configure, ./scripts/start, or other Malcolm control scripts.

    github.com/idaholab/Malcolm/co

    • Features and enhancements

      • Add IEC 60870-5-104 (IEC 104) support using the CERT.LV spicy-iec104 Zeek plugin, including Zeek log ingestion, ECS field mapping, Arkime fields, and an IEC 104 dashboard #939
      • Make LOGSTASH_NETBOX_ENRICHMENT_DATASETS more flexible: it now accepts default, ics/ot, all, explicit provider.dataset values, and combinations such as default,ics #1037
      • Allow LOGSTASH_NETBOX_ENRICHMENT_DATASETS to be configured through checkboxes in the configuration TUI #1033
      • Improve ./scripts/start error messages by listing missing or invalid authentication-related files instead of reporting only a generic authentication setup failure #865
      • Have system-quickstart detect and prepopulate existing time synchronization settings when rerun #992
    • 🛡️ Security Remediation & Hardening

      • Fix an RBAC bypass caused by URI normalization differences between Nginx location matching and the Lua authorization layer CVE-2026-63177 #1042
      • Fix path traversal in archive extraction directory handling by validating resolved paths and using libarchive's secure extraction flags CVE-2026-63134 #1040
      • Limit archive entry count, nesting depth, and total expanded size to prevent inode- and resource-exhaustion denial of service during extraction CVE-2026-63133 #1041
      • Mark OpenID Connect session cookies as secure and improve handling of externally forwarded HTTPS schemes
    • 🐛 Bug fixes

      • Allow the configuration TUI to reset supported variables back to empty values after installation #1024, #1030
      • Fix the broken signal chain in docker-uid-gid-setup.sh so signals reach the final process after dropping privileges #1039 to ensure clean shutdown of containers
      • Fix PostgreSQL being reported unhealthy after a major-version upgrade, improve upgrade-state handling, and perform required post-upgrade extension and collation maintenance #1038
      • Fix the Nginx Lua/OpenID Connect helper not honoring user-provided CA certificates for KeyCloak when KEYCLOAK_SSL_VERIFY=true #1035
      • Restore curl to the the htadmin container for use by the health check script #1029
      • Reduce the size of the OpenSearch Dashboards image by copying only the permissions data needed from its upstream image layer #1031
      • Fix JSON handling of several Zeek fields whose names contain dots by normalizing them to underscore-separated field names
      • Fix additional Zeek and Suricata field normalization and ECS mapping inconsistencies found while updating dashboards and index templates
    • Component version updates

    • 🧹 Code and project maintenance

      • Broad spelling, grammar, naming consistency, and documentation cleanup across scripts, configuration, dashboards, and documentation #990
      • Expand and restructure documentation to provide better project context for developers and LLM-assisted code analysis #964
      • Improve installer validation, environment-variable mapping tests, and configuration item metadata
      • Refresh dashboards, index templates, field mappings, protocol documentation, and navigation links
    • 📄 Configuration changes for Malcolm (in environment variables in ./config/). The Malcolm control script (e.g., ./scripts/status, ./scripts/start) automatically handles creation and migration of variables according to ./config/env-var-actions.yml.

      • LOGSTASH_NETBOX_ENRICHMENT_DATASETS in logstash.env now defaults to default and may contain default, ics/ot, all, explicit provider.dataset values, or a comma-separated combination of these values
      • ZEEK_DISABLE_ICS_IEC104 in zeek.env controls whether the IEC 104 Zeek plugin is disabled
      • SAFE_EXTRACT_MAX_ENTRIES, SAFE_EXTRACT_MAX_DEPTH, and SAFE_EXTRACT_MAX_BYTES in upload-common.env set archive extraction resource limits for uploaded archive files (e.g., containing Zeek logs for processing); their defaults are 5,000 entries, 20 directory levels, and 4 GiB of expanded data
    • Errata

      • Post-release, a Strelka bug was found which can cause the strelka-backend container's work process to crash on aarch64 platforms (cisagov#1046). A followup v26.07.1 release addressing this issue is forthcoming.

    Malcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻‍♀️.

    Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.

    Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.

    As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.

    #Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL

  2. CW: release notes for Malcolm v26.07.0, a network traffic analysis tool suite for network security monitoring

    Malcolm v26.07.0 adds IEC 60870-5-104 (IEC 104) protocol support using CERT.LV's Zeek plugin, including Logstash parsing, ECS normalization, Arkime fields, and a new OpenSearch Dashboards dashboard. This release also fixes three archive extraction and authentication security vulnerabilities; improves NetBox enrichment configuration; and addresses PostgreSQL major version upgrade, custom CA certificate for KeyCloak, container health check, privilege-drop signal chaining, and configuration script issues. Arkime, Zeek, Fluent Bit, Filebeat, Logstash, Supercronic, and Alpine-based images have been updated as well.

    If you are upgrading from an existing Malcolm installation, run ./scripts/status for Malcolm to migrate some settings prior to running ./scripts/configure, ./scripts/start, or other Malcolm control scripts.

    github.com/idaholab/Malcolm/co

    • Features and enhancements

      • Add IEC 60870-5-104 (IEC 104) support using the CERT.LV spicy-iec104 Zeek plugin, including Zeek log ingestion, ECS field mapping, Arkime fields, and an IEC 104 dashboard #939
      • Make LOGSTASH_NETBOX_ENRICHMENT_DATASETS more flexible: it now accepts default, ics/ot, all, explicit provider.dataset values, and combinations such as default,ics #1037
      • Allow LOGSTASH_NETBOX_ENRICHMENT_DATASETS to be configured through checkboxes in the configuration TUI #1033
      • Improve ./scripts/start error messages by listing missing or invalid authentication-related files instead of reporting only a generic authentication setup failure #865
      • Have system-quickstart detect and prepopulate existing time synchronization settings when rerun #992
    • 🛡️ Security Remediation & Hardening

      • Fix an RBAC bypass caused by URI normalization differences between Nginx location matching and the Lua authorization layer CVE-2026-63177 #1042
      • Fix path traversal in archive extraction directory handling by validating resolved paths and using libarchive's secure extraction flags CVE-2026-63134 #1040
      • Limit archive entry count, nesting depth, and total expanded size to prevent inode- and resource-exhaustion denial of service during extraction CVE-2026-63133 #1041
      • Mark OpenID Connect session cookies as secure and improve handling of externally forwarded HTTPS schemes
    • 🐛 Bug fixes

      • Allow the configuration TUI to reset supported variables back to empty values after installation #1024, #1030
      • Fix the broken signal chain in docker-uid-gid-setup.sh so signals reach the final process after dropping privileges #1039 to ensure clean shutdown of containers
      • Fix PostgreSQL being reported unhealthy after a major-version upgrade, improve upgrade-state handling, and perform required post-upgrade extension and collation maintenance #1038
      • Fix the Nginx Lua/OpenID Connect helper not honoring user-provided CA certificates for KeyCloak when KEYCLOAK_SSL_VERIFY=true #1035
      • Restore curl to the the htadmin container for use by the health check script #1029
      • Reduce the size of the OpenSearch Dashboards image by copying only the permissions data needed from its upstream image layer #1031
      • Fix JSON handling of several Zeek fields whose names contain dots by normalizing them to underscore-separated field names
      • Fix additional Zeek and Suricata field normalization and ECS mapping inconsistencies found while updating dashboards and index templates
    • Component version updates

    • 🧹 Code and project maintenance

      • Broad spelling, grammar, naming consistency, and documentation cleanup across scripts, configuration, dashboards, and documentation #990
      • Expand and restructure documentation to provide better project context for developers and LLM-assisted code analysis #964
      • Improve installer validation, environment-variable mapping tests, and configuration item metadata
      • Refresh dashboards, index templates, field mappings, protocol documentation, and navigation links
    • 📄 Configuration changes for Malcolm (in environment variables in ./config/). The Malcolm control script (e.g., ./scripts/status, ./scripts/start) automatically handles creation and migration of variables according to ./config/env-var-actions.yml.

      • LOGSTASH_NETBOX_ENRICHMENT_DATASETS in logstash.env now defaults to default and may contain default, ics/ot, all, explicit provider.dataset values, or a comma-separated combination of these values
      • ZEEK_DISABLE_ICS_IEC104 in zeek.env controls whether the IEC 104 Zeek plugin is disabled
      • SAFE_EXTRACT_MAX_ENTRIES, SAFE_EXTRACT_MAX_DEPTH, and SAFE_EXTRACT_MAX_BYTES in upload-common.env set archive extraction resource limits for uploaded archive files (e.g., containing Zeek logs for processing); their defaults are 5,000 entries, 20 directory levels, and 4 GiB of expanded data
    • Errata

      • Post-release, a Strelka bug was found which can cause the strelka-backend container's work process to crash on aarch64 platforms (cisagov#1046). A followup v26.07.1 release addressing this issue is forthcoming.

    Malcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻‍♀️.

    Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.

    Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.

    As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.

    #Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL

  3. CW: release notes for Malcolm v26.07.0, a network traffic analysis tool suite for network security monitoring

    Malcolm v26.07.0 adds IEC 60870-5-104 (IEC 104) protocol support using CERT.LV's Zeek plugin, including Logstash parsing, ECS normalization, Arkime fields, and a new OpenSearch Dashboards dashboard. This release also fixes three archive extraction and authentication security vulnerabilities; improves NetBox enrichment configuration; and addresses PostgreSQL major version upgrade, custom CA certificate for KeyCloak, container health check, privilege-drop signal chaining, and configuration script issues. Arkime, Zeek, Fluent Bit, Filebeat, Logstash, Supercronic, and Alpine-based images have been updated as well.

    If you are upgrading from an existing Malcolm installation, run ./scripts/status for Malcolm to migrate some settings prior to running ./scripts/configure, ./scripts/start, or other Malcolm control scripts.

    github.com/idaholab/Malcolm/co

    • Features and enhancements

      • Add IEC 60870-5-104 (IEC 104) support using the CERT.LV spicy-iec104 Zeek plugin, including Zeek log ingestion, ECS field mapping, Arkime fields, and an IEC 104 dashboard #939
      • Make LOGSTASH_NETBOX_ENRICHMENT_DATASETS more flexible: it now accepts default, ics/ot, all, explicit provider.dataset values, and combinations such as default,ics #1037
      • Allow LOGSTASH_NETBOX_ENRICHMENT_DATASETS to be configured through checkboxes in the configuration TUI #1033
      • Improve ./scripts/start error messages by listing missing or invalid authentication-related files instead of reporting only a generic authentication setup failure #865
      • Have system-quickstart detect and prepopulate existing time synchronization settings when rerun #992
    • 🛡️ Security Remediation & Hardening

      • Fix an RBAC bypass caused by URI normalization differences between Nginx location matching and the Lua authorization layer CVE-2026-63177 #1042
      • Fix path traversal in archive extraction directory handling by validating resolved paths and using libarchive's secure extraction flags CVE-2026-63134 #1040
      • Limit archive entry count, nesting depth, and total expanded size to prevent inode- and resource-exhaustion denial of service during extraction CVE-2026-63133 #1041
      • Mark OpenID Connect session cookies as secure and improve handling of externally forwarded HTTPS schemes
    • 🐛 Bug fixes

      • Allow the configuration TUI to reset supported variables back to empty values after installation #1024, #1030
      • Fix the broken signal chain in docker-uid-gid-setup.sh so signals reach the final process after dropping privileges #1039 to ensure clean shutdown of containers
      • Fix PostgreSQL being reported unhealthy after a major-version upgrade, improve upgrade-state handling, and perform required post-upgrade extension and collation maintenance #1038
      • Fix the Nginx Lua/OpenID Connect helper not honoring user-provided CA certificates for KeyCloak when KEYCLOAK_SSL_VERIFY=true #1035
      • Restore curl to the the htadmin container for use by the health check script #1029
      • Reduce the size of the OpenSearch Dashboards image by copying only the permissions data needed from its upstream image layer #1031
      • Fix JSON handling of several Zeek fields whose names contain dots by normalizing them to underscore-separated field names
      • Fix additional Zeek and Suricata field normalization and ECS mapping inconsistencies found while updating dashboards and index templates
    • Component version updates

    • 🧹 Code and project maintenance

      • Broad spelling, grammar, naming consistency, and documentation cleanup across scripts, configuration, dashboards, and documentation #990
      • Expand and restructure documentation to provide better project context for developers and LLM-assisted code analysis #964
      • Improve installer validation, environment-variable mapping tests, and configuration item metadata
      • Refresh dashboards, index templates, field mappings, protocol documentation, and navigation links
    • 📄 Configuration changes for Malcolm (in environment variables in ./config/). The Malcolm control script (e.g., ./scripts/status, ./scripts/start) automatically handles creation and migration of variables according to ./config/env-var-actions.yml.

      • LOGSTASH_NETBOX_ENRICHMENT_DATASETS in logstash.env now defaults to default and may contain default, ics/ot, all, explicit provider.dataset values, or a comma-separated combination of these values
      • ZEEK_DISABLE_ICS_IEC104 in zeek.env controls whether the IEC 104 Zeek plugin is disabled
      • SAFE_EXTRACT_MAX_ENTRIES, SAFE_EXTRACT_MAX_DEPTH, and SAFE_EXTRACT_MAX_BYTES in upload-common.env set archive extraction resource limits for uploaded archive files (e.g., containing Zeek logs for processing); their defaults are 5,000 entries, 20 directory levels, and 4 GiB of expanded data
    • Errata

      • Post-release, a Strelka bug was found which can cause the strelka-backend container's work process to crash on aarch64 platforms (cisagov#1046). A followup v26.07.1 release addressing this issue is forthcoming.

    Malcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻‍♀️.

    Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.

    Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.

    As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.

    #Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL

  4. CW: release notes for Malcolm v26.07.0, a network traffic analysis tool suite for network security monitoring

    Malcolm v26.07.0 adds IEC 60870-5-104 (IEC 104) protocol support using CERT.LV's Zeek plugin, including Logstash parsing, ECS normalization, Arkime fields, and a new OpenSearch Dashboards dashboard. This release also fixes three archive extraction and authentication security vulnerabilities; improves NetBox enrichment configuration; and addresses PostgreSQL major version upgrade, custom CA certificate for KeyCloak, container health check, privilege-drop signal chaining, and configuration script issues. Arkime, Zeek, Fluent Bit, Filebeat, Logstash, Supercronic, and Alpine-based images have been updated as well.

    If you are upgrading from an existing Malcolm installation, run ./scripts/status for Malcolm to migrate some settings prior to running ./scripts/configure, ./scripts/start, or other Malcolm control scripts.

    github.com/idaholab/Malcolm/co

    • Features and enhancements

      • Add IEC 60870-5-104 (IEC 104) support using the CERT.LV spicy-iec104 Zeek plugin, including Zeek log ingestion, ECS field mapping, Arkime fields, and an IEC 104 dashboard #939
      • Make LOGSTASH_NETBOX_ENRICHMENT_DATASETS more flexible: it now accepts default, ics/ot, all, explicit provider.dataset values, and combinations such as default,ics #1037
      • Allow LOGSTASH_NETBOX_ENRICHMENT_DATASETS to be configured through checkboxes in the configuration TUI #1033
      • Improve ./scripts/start error messages by listing missing or invalid authentication-related files instead of reporting only a generic authentication setup failure #865
      • Have system-quickstart detect and prepopulate existing time synchronization settings when rerun #992
    • 🛡️ Security Remediation & Hardening

      • Fix an RBAC bypass caused by URI normalization differences between Nginx location matching and the Lua authorization layer CVE-2026-63177 #1042
      • Fix path traversal in archive extraction directory handling by validating resolved paths and using libarchive's secure extraction flags CVE-2026-63134 #1040
      • Limit archive entry count, nesting depth, and total expanded size to prevent inode- and resource-exhaustion denial of service during extraction CVE-2026-63133 #1041
      • Mark OpenID Connect session cookies as secure and improve handling of externally forwarded HTTPS schemes
    • 🐛 Bug fixes

      • Allow the configuration TUI to reset supported variables back to empty values after installation #1024, #1030
      • Fix the broken signal chain in docker-uid-gid-setup.sh so signals reach the final process after dropping privileges #1039 to ensure clean shutdown of containers
      • Fix PostgreSQL being reported unhealthy after a major-version upgrade, improve upgrade-state handling, and perform required post-upgrade extension and collation maintenance #1038
      • Fix the Nginx Lua/OpenID Connect helper not honoring user-provided CA certificates for KeyCloak when KEYCLOAK_SSL_VERIFY=true #1035
      • Restore curl to the the htadmin container for use by the health check script #1029
      • Reduce the size of the OpenSearch Dashboards image by copying only the permissions data needed from its upstream image layer #1031
      • Fix JSON handling of several Zeek fields whose names contain dots by normalizing them to underscore-separated field names
      • Fix additional Zeek and Suricata field normalization and ECS mapping inconsistencies found while updating dashboards and index templates
    • Component version updates

    • 🧹 Code and project maintenance

      • Broad spelling, grammar, naming consistency, and documentation cleanup across scripts, configuration, dashboards, and documentation #990
      • Expand and restructure documentation to provide better project context for developers and LLM-assisted code analysis #964
      • Improve installer validation, environment-variable mapping tests, and configuration item metadata
      • Refresh dashboards, index templates, field mappings, protocol documentation, and navigation links
    • 📄 Configuration changes for Malcolm (in environment variables in ./config/). The Malcolm control script (e.g., ./scripts/status, ./scripts/start) automatically handles creation and migration of variables according to ./config/env-var-actions.yml.

      • LOGSTASH_NETBOX_ENRICHMENT_DATASETS in logstash.env now defaults to default and may contain default, ics/ot, all, explicit provider.dataset values, or a comma-separated combination of these values
      • ZEEK_DISABLE_ICS_IEC104 in zeek.env controls whether the IEC 104 Zeek plugin is disabled
      • SAFE_EXTRACT_MAX_ENTRIES, SAFE_EXTRACT_MAX_DEPTH, and SAFE_EXTRACT_MAX_BYTES in upload-common.env set archive extraction resource limits for uploaded archive files (e.g., containing Zeek logs for processing); their defaults are 5,000 entries, 20 directory levels, and 4 GiB of expanded data
    • Errata

      • Post-release, a Strelka bug was found which can cause the strelka-backend container's work process to crash on aarch64 platforms (cisagov#1046). A followup v26.07.1 release addressing this issue is forthcoming.

    Malcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻‍♀️.

    Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.

    Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.

    As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.

    #Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL

  5. CW: release notes for Malcolm v26.07.0, a network traffic analysis tool suite for network security monitoring

    Malcolm v26.07.0 adds IEC 60870-5-104 (IEC 104) protocol support using CERT.LV's Zeek plugin, including Logstash parsing, ECS normalization, Arkime fields, and a new OpenSearch Dashboards dashboard. This release also fixes three archive extraction and authentication security vulnerabilities; improves NetBox enrichment configuration; and addresses PostgreSQL major version upgrade, custom CA certificate for KeyCloak, container health check, privilege-drop signal chaining, and configuration script issues. Arkime, Zeek, Fluent Bit, Filebeat, Logstash, Supercronic, and Alpine-based images have been updated as well.

    If you are upgrading from an existing Malcolm installation, run ./scripts/status for Malcolm to migrate some settings prior to running ./scripts/configure, ./scripts/start, or other Malcolm control scripts.

    github.com/idaholab/Malcolm/co

    • Features and enhancements

      • Add IEC 60870-5-104 (IEC 104) support using the CERT.LV spicy-iec104 Zeek plugin, including Zeek log ingestion, ECS field mapping, Arkime fields, and an IEC 104 dashboard #939
      • Make LOGSTASH_NETBOX_ENRICHMENT_DATASETS more flexible: it now accepts default, ics/ot, all, explicit provider.dataset values, and combinations such as default,ics #1037
      • Allow LOGSTASH_NETBOX_ENRICHMENT_DATASETS to be configured through checkboxes in the configuration TUI #1033
      • Improve ./scripts/start error messages by listing missing or invalid authentication-related files instead of reporting only a generic authentication setup failure #865
      • Have system-quickstart detect and prepopulate existing time synchronization settings when rerun #992
    • 🛡️ Security Remediation & Hardening

      • Fix an RBAC bypass caused by URI normalization differences between Nginx location matching and the Lua authorization layer CVE-2026-63177 #1042
      • Fix path traversal in archive extraction directory handling by validating resolved paths and using libarchive's secure extraction flags CVE-2026-63134 #1040
      • Limit archive entry count, nesting depth, and total expanded size to prevent inode- and resource-exhaustion denial of service during extraction CVE-2026-63133 #1041
      • Mark OpenID Connect session cookies as secure and improve handling of externally forwarded HTTPS schemes
    • 🐛 Bug fixes

      • Allow the configuration TUI to reset supported variables back to empty values after installation #1024, #1030
      • Fix the broken signal chain in docker-uid-gid-setup.sh so signals reach the final process after dropping privileges #1039 to ensure clean shutdown of containers
      • Fix PostgreSQL being reported unhealthy after a major-version upgrade, improve upgrade-state handling, and perform required post-upgrade extension and collation maintenance #1038
      • Fix the Nginx Lua/OpenID Connect helper not honoring user-provided CA certificates for KeyCloak when KEYCLOAK_SSL_VERIFY=true #1035
      • Restore curl to the the htadmin container for use by the health check script #1029
      • Reduce the size of the OpenSearch Dashboards image by copying only the permissions data needed from its upstream image layer #1031
      • Fix JSON handling of several Zeek fields whose names contain dots by normalizing them to underscore-separated field names
      • Fix additional Zeek and Suricata field normalization and ECS mapping inconsistencies found while updating dashboards and index templates
    • Component version updates

    • 🧹 Code and project maintenance

      • Broad spelling, grammar, naming consistency, and documentation cleanup across scripts, configuration, dashboards, and documentation #990
      • Expand and restructure documentation to provide better project context for developers and LLM-assisted code analysis #964
      • Improve installer validation, environment-variable mapping tests, and configuration item metadata
      • Refresh dashboards, index templates, field mappings, protocol documentation, and navigation links
    • 📄 Configuration changes for Malcolm (in environment variables in ./config/). The Malcolm control script (e.g., ./scripts/status, ./scripts/start) automatically handles creation and migration of variables according to ./config/env-var-actions.yml.

      • LOGSTASH_NETBOX_ENRICHMENT_DATASETS in logstash.env now defaults to default and may contain default, ics/ot, all, explicit provider.dataset values, or a comma-separated combination of these values
      • ZEEK_DISABLE_ICS_IEC104 in zeek.env controls whether the IEC 104 Zeek plugin is disabled
      • SAFE_EXTRACT_MAX_ENTRIES, SAFE_EXTRACT_MAX_DEPTH, and SAFE_EXTRACT_MAX_BYTES in upload-common.env set archive extraction resource limits for uploaded archive files (e.g., containing Zeek logs for processing); their defaults are 5,000 entries, 20 directory levels, and 4 GiB of expanded data
    • Errata

      • Post-release, a Strelka bug was found which can cause the strelka-backend container's work process to crash on aarch64 platforms (cisagov#1046). A followup v26.07.1 release addressing this issue is forthcoming.

    Malcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻‍♀️.

    Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.

    Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.

    As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.

    #Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL

  6. How to Install #Zammad on #AlmaLinux #VPS (10-Minute Quick-Start Guide) This article provides a guide on how to install Zammad on #AlmaLinux VPS.

    If you're looking to run a robust open-source #helpdesk on your AlmaLinux VPS, Zammad is a great pick. It's modern, feature-packed, and supports everything from ticketing to chat and reporting. This guide ...
    Continued 👉 blog.radwebhosting.com/how-to- #selfhosting #elasticsearch #opensource #letsencrypt #certbot #customersupportplatform #selfhosted #ticket

  7. How to Install #Zammad on #AlmaLinux #VPS (10-Minute Quick-Start Guide) This article provides a guide on how to install Zammad on #AlmaLinux VPS.

    If you're looking to run a robust open-source #helpdesk on your AlmaLinux VPS, Zammad is a great pick. It's modern, feature-packed, and supports everything from ticketing to chat and reporting. This guide ...
    Continued 👉 blog.radwebhosting.com/how-to- #selfhosting #elasticsearch #opensource #letsencrypt #certbot #customersupportplatform #selfhosted #ticket

  8. How to Deploy #Forem on Rocky Linux #VPS This article provides a guide detailing how to deploy Forem on Rocky Linux VPS.
    What is Forem?
    Forem is a robust, open-source platform for building communities like DEV.to. Deploying it on Rocky Linux involves setting up dependencies like PostgreSQL, ...
    Continued 👉 blog.radwebhosting.com/deploy- #rockylinux #postgresql #reverseproxy #forumsoftware #elasticsearch #rubyonrails #redis #sidekiq #selfhosting #rubygems #selfhosted #letsencrypt #forum #opensource

  9. How to Deploy #Forem on Rocky Linux #VPS This article provides a guide detailing how to deploy Forem on Rocky Linux VPS.
    What is Forem?
    Forem is a robust, open-source platform for building communities like DEV.to. Deploying it on Rocky Linux involves setting up dependencies like PostgreSQL, ...
    Continued 👉 blog.radwebhosting.com/deploy- #rockylinux #postgresql #reverseproxy #forumsoftware #elasticsearch #rubyonrails #redis #sidekiq #selfhosting #rubygems #selfhosted #letsencrypt #forum #opensource

  10. How to Deploy #Forem on Rocky Linux #VPS This article provides a guide detailing how to deploy Forem on Rocky Linux VPS.
    What is Forem?
    Forem is a robust, open-source platform for building communities like DEV.to. Deploying it on Rocky Linux involves setting up dependencies like PostgreSQL, ...
    Continued 👉 blog.radwebhosting.com/deploy- #rockylinux #postgresql #reverseproxy #forumsoftware #elasticsearch #rubyonrails #redis #sidekiq #selfhosting #rubygems #selfhosted #letsencrypt #forum #opensource

  11. How to Deploy #Forem on Rocky Linux #VPS This article provides a guide detailing how to deploy Forem on Rocky Linux VPS.
    What is Forem?
    Forem is a robust, open-source platform for building communities like DEV.to. Deploying it on Rocky Linux involves setting up dependencies like PostgreSQL, ...
    Continued 👉 blog.radwebhosting.com/deploy- #rockylinux #postgresql #reverseproxy #forumsoftware #elasticsearch #rubyonrails #redis #sidekiq #selfhosting #rubygems #selfhosted #letsencrypt #forum #opensource

  12. How to Install #Zammad on #AlmaLinux #VPS (10-Minute Quick-Start Guide) This article provides a guide on how to install Zammad on #AlmaLinux VPS.

    If you're looking to run a robust open-source #helpdesk on your AlmaLinux VPS, Zammad is a great pick. It's modern, feature-packed, and supports everything from ticketing to chat and reporting. This guide ...
    Continued 👉 blog.radwebhosting.com/how-to- #letsencrypt #elasticsearch #opensource #selfhosted #ticket #customersupportplatform #selfhosting #certbot

  13. How to Deploy #Forem on Rocky Linux #VPS This article provides a guide detailing how to deploy Forem on Rocky Linux VPS.
    What is Forem?
    Forem is a robust, open-source platform for building communities like DEV.to. Deploying it on Rocky Linux involves setting up dependencies like PostgreSQL, ...
    Continued 👉 blog.radwebhosting.com/deploy- #postgresql #rubyonrails #forumsoftware #rockylinux #rubygems #opensource #elasticsearch #forum #selfhosted #letsencrypt #reverseproxy #selfhosting #sidekiq #redis

  14. How to Deploy #Forem on Rocky Linux #VPS This article provides a guide detailing how to deploy Forem on Rocky Linux VPS.
    What is Forem?
    Forem is a robust, open-source platform for building communities like DEV.to. Deploying it on Rocky Linux involves setting up dependencies like PostgreSQL, ...
    Continued 👉 blog.radwebhosting.com/deploy- #postgresql #rubyonrails #forumsoftware #rockylinux #rubygems #opensource #elasticsearch #forum #selfhosted #letsencrypt #reverseproxy #selfhosting #sidekiq #redis

  15. How to Deploy #Forem on Rocky Linux #VPS This article provides a guide detailing how to deploy Forem on Rocky Linux VPS.
    What is Forem?
    Forem is a robust, open-source platform for building communities like DEV.to. Deploying it on Rocky Linux involves setting up dependencies like PostgreSQL, ...
    Continued 👉 blog.radwebhosting.com/deploy- #postgresql #rubyonrails #forumsoftware #rockylinux #rubygems #opensource #elasticsearch #forum #selfhosted #letsencrypt #reverseproxy #selfhosting #sidekiq #redis

  16. New release 0.0.26 of esctl, a cli tool to manage elasticsearch:

    - add ES/QL search support
    - enhanced API Repl
    - add json pager support to API repl
    - add shard allocation explain
    - enhance cluster status, show health
    - add show license
    - enhance completion
    - add usage cmd to show esctl features
    - speed up cluster LS
    - enhance node commands
    - show ilm policy as tree (-t)
    - add cluster reroute support
    - add ilm forecast

    #elasticsearch #golang #cli #oss #esctl

    codeberg.org/scip/esctl

  17. Elasticsearch snapshot to S3: register repo + validate integrity via write/read checksum cycle. Snapshot indices into compressed shard blobs. Verify reachability and consistency. Practical snippet for ES 7.x/8.x. #elasticsearch #snapshot #s3

    valtersit.com/vault/cluster-sn

  18. For many years, syslog-ng used , where libraries were unavailable. However, over the years native C libraries became available for and , and practically disappeared. As a “#scream ”, I am going to disable Java support in all of my syslog-ng packages.

    syslog-ng.com/community/b/blog

  19. For many years, syslog-ng used #Java, where #C libraries were unavailable. However, over the years native C libraries became available for #Elasticsearch and #Kafka, and #HDFS practically disappeared. As a “#scream #test”, I am going to disable Java support in all of my syslog-ng packages.

    syslog-ng.com/community/b/blog

  20. For many years, syslog-ng used #Java, where #C libraries were unavailable. However, over the years native C libraries became available for #Elasticsearch and #Kafka, and #HDFS practically disappeared. As a “#scream #test”, I am going to disable Java support in all of my syslog-ng packages.

    syslog-ng.com/community/b/blog

  21. For many years, syslog-ng used #Java, where #C libraries were unavailable. However, over the years native C libraries became available for #Elasticsearch and #Kafka, and #HDFS practically disappeared. As a “#scream #test”, I am going to disable Java support in all of my syslog-ng packages.

    syslog-ng.com/community/b/blog

  22. For many years, syslog-ng used #Java, where #C libraries were unavailable. However, over the years native C libraries became available for #Elasticsearch and #Kafka, and #HDFS practically disappeared. As a “#scream #test”, I am going to disable Java support in all of my syslog-ng packages.

    syslog-ng.com/community/b/blog

  23. How to Install #Zammad on #AlmaLinux #VPS (10-Minute Quick-Start Guide) This article provides a guide on how to install Zammad on #AlmaLinux VPS.

    If you're looking to run a robust open-source #helpdesk on your AlmaLinux VPS, Zammad is a great pick. It's modern, feature-packed, and supports everything from ticketing to chat and reporting. This guide ...
    Continued 👉 blog.radwebhosting.com/how-to- #selfhosting #elasticsearch #selfhosted #customersupportplatform #opensource #ticket #certbot #letsencrypt

  24. How to Install #Zammad on #AlmaLinux #VPS (10-Minute Quick-Start Guide) This article provides a guide on how to install Zammad on #AlmaLinux VPS.

    If you're looking to run a robust open-source #helpdesk on your AlmaLinux VPS, Zammad is a great pick. It's modern, feature-packed, and supports everything from ticketing to chat and reporting. This guide ...
    Continued 👉 blog.radwebhosting.com/how-to- #selfhosting #elasticsearch #selfhosted #customersupportplatform #opensource #ticket #certbot #letsencrypt

  25. How to Deploy #Forem on Rocky Linux #VPS This article provides a guide detailing how to deploy Forem on Rocky Linux VPS.
    What is Forem?
    Forem is a robust, open-source platform for building communities like DEV.to. Deploying it on Rocky Linux involves setting up dependencies like PostgreSQL, ...
    Continued 👉 blog.radwebhosting.com/deploy- #forum #sidekiq #elasticsearch #rubygems #reverseproxy #selfhosted #rubyonrails #letsencrypt #redis #selfhosting #postgresql #forumsoftware #opensource #rockylinux

  26. How to Deploy #Forem on Rocky Linux #VPS This article provides a guide detailing how to deploy Forem on Rocky Linux VPS.
    What is Forem?
    Forem is a robust, open-source platform for building communities like DEV.to. Deploying it on Rocky Linux involves setting up dependencies like PostgreSQL, ...
    Continued 👉 blog.radwebhosting.com/deploy- #forum #sidekiq #elasticsearch #rubygems #reverseproxy #selfhosted #rubyonrails #letsencrypt #redis #selfhosting #postgresql #forumsoftware #opensource #rockylinux

  27. How to Deploy #Forem on Rocky Linux #VPS This article provides a guide detailing how to deploy Forem on Rocky Linux VPS.
    What is Forem?
    Forem is a robust, open-source platform for building communities like DEV.to. Deploying it on Rocky Linux involves setting up dependencies like PostgreSQL, ...
    Continued 👉 blog.radwebhosting.com/deploy- #forum #sidekiq #elasticsearch #rubygems #reverseproxy #selfhosted #rubyonrails #letsencrypt #redis #selfhosting #postgresql #forumsoftware #opensource #rockylinux

  28. How to Deploy #Forem on Rocky Linux #VPS This article provides a guide detailing how to deploy Forem on Rocky Linux VPS.
    What is Forem?
    Forem is a robust, open-source platform for building communities like DEV.to. Deploying it on Rocky Linux involves setting up dependencies like PostgreSQL, ...
    Continued 👉 blog.radwebhosting.com/deploy- #forum #sidekiq #elasticsearch #rubygems #reverseproxy #selfhosted #rubyonrails #letsencrypt #redis #selfhosting #postgresql #forumsoftware #opensource #rockylinux

  29. How to Install #Zammad on #AlmaLinux #VPS (10-Minute Quick-Start Guide) This article provides a guide on how to install Zammad on #AlmaLinux VPS.

    If you're looking to run a robust open-source #helpdesk on your AlmaLinux VPS, Zammad is a great pick. It's modern, feature-packed, and supports everything from ticketing to chat and reporting. This guide ...
    Continued 👉 blog.radwebhosting.com/how-to- #letsencrypt #opensource #certbot #selfhosted #ticket #elasticsearch #customersupportplatform #selfhosting

  30. Elastic has open-sourced Atlas, a memory system for AI agents built on Elasticsearch.

    Key features:
    • 3 categories of memory
    • MCP integration
    • Per-user memory isolation

    How does it perform? Atlas hit a 0.89 Recall at 10 on question-answering tasks.

    🔗 Read more: bit.ly/3QWmzJn

    #AI #Elasticsearch #AIAgents #MCP #OpenSource #InfoQ

  31. Elastic has open-sourced Atlas, a memory system for AI agents built on Elasticsearch.

    Key features:
    • 3 categories of memory
    • MCP integration
    • Per-user memory isolation

    How does it perform? Atlas hit a 0.89 Recall at 10 on question-answering tasks.

    🔗 Read more: bit.ly/3QWmzJn

  32. Ah yes, good ol' super efficient #Elasticsearch

    (To be fair, it's currently indexing about 220GB of E-Mails and Media-Attachments of said E-Mails.)