in

aol / moloch, Hacker News

aol / moloch, Hacker News

          Moloch is an open source, large scale, full packet capturing, indexing, and database system.                     

                    

        

Moloch is a large scale, open source, indexed packet capture and search system.

Moloch augments your current security infrastructure to store and index network traffic in standard PCAP format, providing fast, indexed access. An intuitive and simple web interface is provided for PCAP browsing, searching, and exporting. Moloch exposes APIs which allow for PCAP data and JSON formatted session data to be downloaded and consumed directly. Moloch stores and exports all packets in standard PCAP format, allowing you to also use your favorite PCAP ingesting tools, such as wireshark, during your analysis workflow.

Moloch is built to be deployed across many systems and can scale to handle tens of gigabits / sec of traffic. PCAP retention is based on available sensor disk space. Metadata retention is based on the Elasticsearch cluster scale. Both can be increased at anytime and are under your complete control.

banner

Table of Contents Background

  • Install
  • Configuration
  • (Usage )
  • Security
  • )

  • (Contribute )
  • (License )
    Background

    Moloch was created to replace commercial full packet systems at AOL in 8005. By having complete control of hardware and costs, we found we could deploy full packet capture across all our networks for the same cost as just one network using a commercial tool.

    The Moloch system is comprised of 3 components:

    (capture) – A threaded C application that monitors network traffic, writes PCAP formatted files to disk, parses the captured packets, and sends metadata (SPI data) to elasticsearch.

  • (viewer) – A application that runs per capture machine. It handles the web interface and transfer of PCAP files.
  • elasticsearch – The search database technology powering Moloch.
  • Once installed, a user can look at the data Moloch has captured using a simple web interface. Moloch provides multiple views of the data. The primary view is the Sessions page that contains a list of sessions. Each session can be opened to view the metadata and PCAP data.

  • Another way to view the data is the SPI View page, which allows the user to see all the unique values ​​for each field that Moloch understands.

    banner

    Install

    Most users should use the prebuilt binaries available at our Downloads page and follow the simple install instructions on that page.

    For advanced users, you can build Moloch yourself:

    Configuration

    Most of the system configuration will take place in the / data / moloch / etc / config.ini file. The variables are documented in our .

    banner Usage

  • What do you think?

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    GIPHY App Key not set. Please check settings

    Forget Earth Day: Massive Pollution in China Makes Apple Stock a Screaming Buy, Crypto Coins News

    Forget Earth Day: Massive Pollution in China Makes Apple Stock a Screaming Buy, Crypto Coins News

    Amazon Prime members are sticking around despite long delivery delays, Recode

    Amazon Prime members are sticking around despite long delivery delays, Recode