Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Malcolm v24.12.0 #615

Merged
merged 55 commits into from
Dec 19, 2024
Merged

Malcolm v24.12.0 #615

merged 55 commits into from
Dec 19, 2024

Conversation

mmguero
Copy link
Collaborator

@mmguero mmguero commented Dec 18, 2024

Malcolm v24.12.0 contains several improvements to the Malcolm configuration script, the Malcolm user interface, and the Malcolm API, as well as component version updates and bug fixes. This release also corresponds with the release of the malcolm-test (cisagov#486), a Malcolm systems testing framework.

v24.11.0...v24.12.0

I discovered that there are some conflicts between ECS's DNS fields (https://www.elastic.co/guide/en/ecs/current/ecs-dns.html) and Arkime's (https://github.com/arkime/arkime/blob/70765f46f6e17b62e405d9cd82d8109030e51bd8/db/db.pl#L4369-L4431) that would result in some issues when opening Zeek dns.log entries in Arkime sessions. So I'm commenting-out some of the ECS DNS normalization here in favor of the Arkime fields.
@mmguero mmguero marked this pull request as draft December 18, 2024 18:49
@mmguero mmguero merged commit d8dabe0 into main Dec 19, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant