ElastiFlow v3.4.2 Release Notes

Release Date: 2019-05-03 // almost 5 years ago
  • ๐Ÿš€ v3.4.2 is a minor release. No migration of data from v3.4.1 to v3.4.2 is required.

    ๐Ÿ’ฅ Breaking Changes

    ๐Ÿš€ If you are upgrading from a release prior to 3.4.0, see the Breaking Changes notice for v3.4.0 below.

    ๐Ÿ†• New Features

    • โž• Added support for Cisco AVC flow records (normalized to ElastiFlow schema)
    • Determine client/server based on SYN+RST TCP flags
    • ๐Ÿ‘Œ Support for Elastic Stack 6.7.x

    โšก๏ธ Updates

    • โž• Added A LOT of new Fortinet App IDs
    • Index Pattern now includes all fields from codec definitions
    • โšก๏ธ Updated GeoLite2-City and GeoLite2-ASN DBs
    • โšก๏ธ Updated IP Reputation dictionary

    ๐Ÿ›  Fixes

    • ๐Ÿ›  Numerous index template fixes
    • โœ‚ Removed duplicate TCP service names
    • ๐Ÿ›  Fixed instances of double close brackets