Network flow analytics (Netflow, sFlow and IPFIX) with the Elastic Stack
ElastiFlow v4.0.1 is a minor release. No migration of data from v4.0.0 to v4.0.1 is required.
WARNING! - If you are using a 3.x or earlier release, please refer to the v4.0.0 Breaking Changes.
bitd
custom formatter.WARNING! - ElastiFlow v4.0.0 is a major release, and now supports Elastic Common Schema (ECS). Due to significant data model changes there is no upgrade/migration from ElastiFlow 3.x. You should either remove all 3.x indices or deploy ElastiFlow 4.0.0 to a separate environment.
ElastiFlow v4.0.0 is built for Elasticsearch and Kibana 7.8.1 and later. No earlier versions will be supported. Please use a prior ElastiFlow release if you cannot yet upgrade to Elastic Stack 7.8.1+.
ElastiFlow v4.0.0 takes advantage of X-Pack Basic features, such as the Maps, SIEM and Logs apps, as well as Index Lifecycle Management (ILM). This means that you must use at least the X-Pack Basic licensed release of the Elastic Stack. The pure Apache 2.0 licensed release of the Elastic Stack will not work without disabling many features.
logstash/elastiflow/user_settings
path.v4.0.0 is a major release. A data migration will be required if you want to have your older data available in 4.0.0. This BETA
release does not yet include a migration method and is intended for testing with new flow data only.
ElastiFlow v4.0.0 is built for Elasticsearch and Kibana 7.5.0 and later. No earlier versions will be supported. Please use a prior ElastiFlow release if you cannot yet upgrade to Elastic Stack 7.5.x.
ElasiFlow v4.0.0 takes advantage of X-Pack Basic features, such as the Maps, SIEM and Logs apps, as well as Index Lifecycle Management (ILM). This means that you must use at least the X-Pack Basic licensed release of the Elastic Stack. The pure Apache 2.0 licensed release of the Elastic Stack will not work without disabling many features.
logstash/elastiflow/user_settings
path.v3.5.3 is a minor release. No migration of data from v3.5.x to v3.5.3 is required.
ElastiFlow v3.5.x provides support Elastic Stack 7.x. The support for document types has been completely removed in Elasticsearch 7.0.0. This has required changes to the index templates provided with ElastiFlow. You MUST first successfully upgrade to Elastic Stack 7.x PRIOR to using ElastiFlow v3.5.3.
v3.5.2 is a minor release. No migration of data from v3.5.1 to v3.5.2 is required.
ElastiFlow v3.5.x provides support Elastic Stack 7.x. The support for document types has been completely removed in Elasticsearch 7.0.0. This has required changes to the index templates provided with ElastiFlow. You MUST first successfully upgrade to Elastic Stack 7.x PRIOR to using ElastiFlow v3.5.2.
logstash_host
.int
.v3.5.1 is a minor release. No migration of data from v3.5.0 to v3.5.1 is required.
ElastiFlow v3.5.x provides support Elastic Stack 7.x. The support for document types has been completely removed in Elasticsearch 7.0.0. This has required changes to the index templates provided with ElastiFlow. You MUST first successfully upgrade to Elastic Stack 7.x PRIOR to using ElastiFlow v3.5.1.
docker-compose.yml
, which prevented the Kibana container from connecting to Elasticsearch.v3.5.0 is a minor release. No migration of data from v3.4.x to v3.5.0 is required.
ElastiFlow v3.5.0 provides support Elastic Stack 7.0.0. The support for document types has been completely removed in Elasticsearch 7.0.0. This has required changes to the index templates provided with ElastiFlow. You MUST first successfully upgrade to Elastic Stack 7.0.x PRIOR to using ElastiFlow v3.5.0.
v3.4.2 is a minor release. No migration of data from v3.4.1 to v3.4.2 is required.
If you are upgrading from a release prior to 3.4.0, see the Breaking Changes notice for v3.4.0 below.
v3.4.1 is a minor release. No migration of data from v3.4.0 to v3.4.1 is required.
If you are upgrading from a release prior to 3.4.0, see the Breaking Changes notice for v3.4.0.
netflow.app_id
.v3.4.0 adds custom field definitions for the Netflow codec. While greatly expanding the number of supported vendor-specific fields, many existing vendor-specific fields have been renamed. The ElastiFlow dashboards in previous releases were based on its normalized flow
schema, or other standard Netflow and IPFIX fields, all of which are unchanged. However it may be necessary to update any Dashboards you created for the old vendor-specific field names to use the new names.
sysctl.d
file to set net.core.rmem_max
translate
filters to use the new option refresh_behaviour
, setting it to replace
tcp
input