arkime/arkime
Arkime is an open source, large scale, full packet capturing, indexing, and database system. observed · 2026-08-28
Health v2 · maintenance only
99/100
- Activity 99
- Release rhythm 98
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 25.5
- age_days: 5171
- days_rel: 14
- days_push: 7
- n_releases_24m: 23
Adoption not part of the score
7459 stars · 1161 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
Arkime is an open-source, large-scale network analysis, full packet capture, and session indexing system that stores traffic in standard PCAP format and indexes searchable metadata in OpenSearch/Elasticsearch. It includes a web UI for browsing and exporting sessions, plus companion tools like Parliament (cluster health) and Cont3xt (indicator enrichment).
Use cases
- capture and index full network packets at scale for security investigations
- search and browse network session metadata with a web interface
- investigate security incidents by drilling from session records down to raw PCAP bytes
- run enriched NetFlow-style metadata-only monitoring without storing full packets
- enrich IOCs like IPs, domains, and hashes using OSINT sources
- monitor health of multiple Arkime capture clusters from one dashboard
- export PCAPs for analysis in tools like Wireshark
When to choose
- you need full packet capture and fast indexed search across tens of gigabits per second of traffic
- you want to augment an existing IDS/SIEM with searchable network session ground truth
- you need self-hosted network security monitoring with standard PCAP storage and APIs
- you want long-retention, metadata-only network visibility on limited disk
When to avoid
- you need a lightweight host-based or endpoint monitoring solution
- you cannot operate an OpenSearch/Elasticsearch cluster or dedicated capture sensors
- you only need simple log aggregation rather than packet-level network analysis
- you require Windows-native deployment, as Arkime targets Linux sensors
Facets
application · maturity active
search-engine monitoring security analytics http-server security networking big-data analytics self-hosted self-hosted network-security-monitoring full-packet-capture pcap nsm elasticsearch opensearch network-forensics ids-augmentation linux docker web-server
7 sources
- readme: https://github.com/arkime/arkime · fetched 2026-08-28 · 44709b69afbc
- homepage: https://arkime.com · fetched 2026-08-29 · 6394955a58d0
- site_page: https://arkime.com/install · fetched 2026-08-29 · d59068612e37
- site_page: https://arkime.com/faq · fetched 2026-08-29 · b33eb28f9f52
- site_page: https://arkime.com/learn · fetched 2026-08-29 · 91462f3f4d07
- site_page: https://arkime.com/parliament · fetched 2026-08-29 · 8cb5c17b7984
- site_page: https://arkime.com/cont3xt · fetched 2026-08-29 · 4a4d1e489ebb
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| arkime/arkime | main | 99 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem