操作系统:Centos7.2
配置:4C8G
下载RPM包:wget https://s3.amazonaws.com/files.molo.ch/builds/centos-7/moloch-2.2.3-1.x86_64.rpm
安装依赖包:
yum -y install perl-libwww-perl perl-JSON libyaml-devel perl-LWP-Protocol-https
安装Elasticsearch:
docker pull elasticsearch:7.6.2
docker run -d --name es -p 9200:9200 -p 9300:9300 -e "discovery.type=single-node" elasticsearch:7.6.2
运行Configure:
rpm -ivh moloch-2.2.3-1.x86_64.rpm
./Configure
这边的错误的意思是我们需要申请一个MaxMind的账号:
/data/moloch/bin/moloch_add_user.sh admin "Admin User" qwerty1234 --admin
# systemctl start molochcapture.service
# systemctl status molochviewer.service
molochviewer.service - Moloch Viewer
Loaded: loaded (/etc/systemd/system/molochviewer.service; disabled; vendor preset: enabled)
Active: active (running) since Wed 2019-05-22 03:15:27 PDT; 4h 45min ago
Main PID: 7979 (sh)
Tasks: 11 (limit: 4915)
CGroup: /system.slice/molochviewer.service
??7979 /bin/sh -c /data/moloch/bin/node viewer.js -c /data/moloch/etc/config.ini >> /data/moloch/logs/viewer.log 2>&1
??7985 /data/moloch/bin/node viewer.js -c /data/moloch/etc/config.ini
/data/moloch/etc/config.ini
./moloch-capture -c ../etc/config.ini
tag号可以自己随意设置
/data/moloch/bin/moloch-capture -c ../etc/config.ini -r /root/dump.pcap --tag test
查找的时候设置好tags == test, 时间选择All就ok了。
https://www.pwnthebox.net/moloch/2019/05/22/installing-moloch.html
原创声明:本文系作者授权腾讯云开发者社区发表,未经许可,不得转载。
如有侵权,请联系 cloudcommunity@tencent.com 删除。
原创声明:本文系作者授权腾讯云开发者社区发表,未经许可,不得转载。
如有侵权,请联系 cloudcommunity@tencent.com 删除。