ElastiFlow v3.5.2 Release Notes

Release Date: 2019-12-17 // over 4 years ago
  • ๐Ÿš€ v3.5.2 is a minor release. No migration of data from v3.5.1 to v3.5.2 is required.

    ๐Ÿ’ฅ Breaking Changes

    ElastiFlow v3.5.x provides support Elastic Stack 7.x. The support for document types has been completely removed in Elasticsearch 7.0.0. This has required changes to the index templates provided with ElastiFlow. You MUST first successfully upgrade to Elastic Stack 7.x PRIOR to using ElastiFlow v3.5.2.

    ๐Ÿ†• New Features

    • โž• Added normalization of WiFi-related Netflow v9 and IPFIX fields.
    • ๐Ÿ”Š The hostname where Logstash is running is provided in the field logstash_host.
    • โž• Added the ability to manually set flow sampling values for IPFIX.

    ๐Ÿ›  Fixes

    • ๐Ÿ›  Fix Cisco vzFlow type for list fields.
    • ๐Ÿ›  Fix Procera IEs incorrectly defined as int.

    โšก๏ธ Updates

    • ๐Ÿ‘Œ Improved the display of rate values in Vega visualizations.
    • โž• Added a lot of new Fortinet application IDs.
    • โšก๏ธ Update IP reputation dictionary and GeoIP DBs.