Skip to content

Missing Fields #675

Closed Answered by mmguero
devilman85 asked this question in Troubleshooting
Discussion options

You must be logged in to vote

Rather than doing it from the command line, probably the safest way to do this would be to:

  1. Stop Malcolm
  2. Go into Kibana on your Elasticsearch cluster
  3. Go into Kibana's index management UI (I'm not much of a Kibana user, I assume it has this?)
  4. Delete all of the indexes that begin with arkime
  5. Start Malcolm back up

Otherwise, use the elasticsearch DELETE api to delete the arkime* indices.

Replies: 8 comments

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by mmguero
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
elastic Related to issue with external ElasticSearch/Kibana output
2 participants
Converted from issue

This discussion was converted from issue #669 on May 15, 2025 12:59.