An open-source, large-scale network packet capture, indexing, and analysis system for security and network monitoring.
Arkime is an open-source network analysis and packet capture system that captures, indexes, and stores network traffic in standard PCAP format. It solves the problem of costly and inflexible commercial full-packet capture systems by providing a scalable, self-hosted alternative for deep network monitoring and security analysis.
Security analysts, network engineers, and DevOps teams who need to monitor, analyze, and retain large volumes of network traffic for troubleshooting, forensics, or threat detection.
Developers choose Arkime for its ability to scale to tens of gigabits per second, its open-source nature that eliminates vendor lock-in, and its integration with existing tools like Wireshark, all while providing a cost-effective alternative to commercial solutions.
Arkime is an open source, large scale, full packet capturing, indexing, and database system.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.
Can scale to tens of gigabits per second across many systems, as explicitly stated in the README for handling high-volume network traffic.
Stores all packets in standard PCAP format, enabling seamless use with tools like Wireshark for deep analysis, as highlighted in the project description.
Open-source nature eliminates vendor lock-in and reduces costs compared to commercial solutions, aligning with its philosophy of providing complete control over hardware and expenses.
Offers an intuitive UI for browsing, searching, and exporting session data, with SPI view and session pages that enhance analyst productivity, as shown in the README screenshots.
Requires setting up multiple components (capture, viewer, Elasticsearch/OpenSearch) and careful configuration, making initial installation and ongoing maintenance resource-intensive.
PCAP retention depends on disk space and metadata on Elasticsearch cluster scale, leading to high hardware costs and operational overhead for storage and indexing.
Primarily designed for storage and indexed access, lacking integrated real-time threat detection or alerting features, which may require additional tools for live monitoring.