Arkime is a scalable network analysis and full packet capture system. It captures network traffic, stores packets in standard PCAP format, and indexes session metadata using OpenSearch or Elasticsearch.
A web interface provides fast searching, browsing and exporting of captured traffic. Arkime is designed to complement existing intrusion detection and security monitoring systems rather than replace them. It can be distributed across multiple systems to analyse networks carrying tens of gigabits of traffic per second.
This is free and open source software.
Key Features
- Captures and stores complete network traffic in standard PCAP format.
- Indexes network session metadata using OpenSearch or Elasticsearch.
- Provides a web interface for browsing, searching and exporting packets.
- Scales across multiple capture systems for high-volume networks.
- Exposes APIs for downloading PCAP files and JSON session data.
- Works with PCAP analysis tools including Wireshark.
- Integrates threat intelligence into session metadata with wiseService.
- Gathers contextual intelligence for investigations with Cont3xt.
- Monitors and provides access to multiple Arkime clusters with Parliament.
- Supports centralised viewers for distributed capture deployments.
- Offers prebuilt packages and official container images.
- Supports HTTPS, proxy-based authentication and OpenSearch security.
Website: github.com/arkime/arkime
Support:
Developer: Arkime
License: Apache License 2.0
Arkime is written in C and JavaScript. Learn C with our recommended free books and free tutorials. Learn JavaScript with our recommended free books and free tutorials.
Related Software
| Network Analyzers | |
|---|---|
| Wireshark | Network protocol analyzer with a rich and powerful feature set |
| Ettercap | Comprehensive suite for man in the middle attacks |
| Kismet | Wireless network and device detector, sniffer, wardriving tool |
| IPTraf-ng | Feature-laden network statistic monitoring tool |
| netsniff-ng | Swiss army knife for daily Linux network plumbing |
| Kyanos | Networking analysis tool using eBPF |
| EtherApe | Graphical network monitor |
| darkstat | Captures network traffic, calculates usage statistics, and serves reports |
| justniffer | Network TCP packet sniffer with reliable TCP flow rebuilding |
| tcpflow | TCP/IP packet demultiplexer |
| tcpdump | Powerful and hugely respected command-line packet analyzer |
| sniffglue | Packet sniffer written in Rust |
| sniffer | Alternative network traffic sniffer |
| dsniff | Collection of tools for network auditing and penetration testing |
| ngrep | grep applied to the network layer |
| Network Monitor | Rreal-time network connection monitoring tool |
| sniffit | CORBA based sniffer system with ncurses interactive mode |
| Jomon | Network forensics and sniffer tool |
Read our verdict in the software roundup.
Explore our comprehensive directory of recommended free and open source software. Our carefully curated collection spans every major software category.This directory is part of our ongoing series of informative articles for Linux enthusiasts. It features hundreds of detailed reviews, along with open source alternatives to proprietary solutions from major corporations such as Google, Microsoft, Apple, Adobe, IBM, Cisco, Oracle, and Autodesk. You’ll also find interesting projects to try, hardware coverage, free programming books and tutorials, and much more. Discovered a useful open source Linux program that we haven’t covered yet? Let us know by completing this form. |


Please read our Comment Policy before commenting.