ElastiFlow v3.4.2 Release Notes
Release Date: 2019-05-03 // almost 5 years ago-
๐ v3.4.2 is a minor release. No migration of data from v3.4.1 to v3.4.2 is required.
๐ฅ Breaking Changes
๐ If you are upgrading from a release prior to 3.4.0, see the Breaking Changes notice for v3.4.0 below.
๐ New Features
- โ Added support for Cisco AVC flow records (normalized to ElastiFlow schema)
- Determine client/server based on SYN+RST TCP flags
- ๐ Support for Elastic Stack 6.7.x
โก๏ธ Updates
- โ Added A LOT of new Fortinet App IDs
- Index Pattern now includes all fields from codec definitions
- โก๏ธ Updated GeoLite2-City and GeoLite2-ASN DBs
- โก๏ธ Updated IP Reputation dictionary
๐ Fixes
- ๐ Numerous index template fixes
- โ Removed duplicate TCP service names
- ๐ Fixed instances of double close brackets