Ross ROSS = Recommend OSS · open-source software intelligence for agents

arkime/arkime

Arkime is an open source, large scale, full packet capturing, indexing, and database system. observed · 2026-08-28

github.com/arkime/arkime · homepage · C · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

99/100

  • Activity 99
  • Release rhythm 98
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 25.5
  • age_days: 5171
  • days_rel: 14
  • days_push: 7
  • n_releases_24m: 23

Full methodology

Adoption not part of the score

7459 stars · 1161 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Arkime is an open-source, large-scale network analysis, full packet capture, and session indexing system that stores traffic in standard PCAP format and indexes searchable metadata in OpenSearch/Elasticsearch. It includes a web UI for browsing and exporting sessions, plus companion tools like Parliament (cluster health) and Cont3xt (indicator enrichment).

Use cases

  • capture and index full network packets at scale for security investigations
  • search and browse network session metadata with a web interface
  • investigate security incidents by drilling from session records down to raw PCAP bytes
  • run enriched NetFlow-style metadata-only monitoring without storing full packets
  • enrich IOCs like IPs, domains, and hashes using OSINT sources
  • monitor health of multiple Arkime capture clusters from one dashboard
  • export PCAPs for analysis in tools like Wireshark

When to choose

  • you need full packet capture and fast indexed search across tens of gigabits per second of traffic
  • you want to augment an existing IDS/SIEM with searchable network session ground truth
  • you need self-hosted network security monitoring with standard PCAP storage and APIs
  • you want long-retention, metadata-only network visibility on limited disk

When to avoid

  • you need a lightweight host-based or endpoint monitoring solution
  • you cannot operate an OpenSearch/Elasticsearch cluster or dedicated capture sensors
  • you only need simple log aggregation rather than packet-level network analysis
  • you require Windows-native deployment, as Arkime targets Linux sensors

Facets

application · maturity active

search-engine monitoring security analytics http-server security networking big-data analytics self-hosted self-hosted network-security-monitoring full-packet-capture pcap nsm elasticsearch opensearch network-forensics ids-augmentation linux docker web-server

7 sources

Member repositories

RepositoryRoleHealth v2
arkime/arkimemain99

For agents

markdown · JSON · MCP: product_card(name="arkime/arkime")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem