Configuration Changes
To improve the consistency of configuration options and prepare for future features on ElastiFlow's roadmap, many of the configuration options have been renamed or otherwise changed. The following is a list of all changes.
:::tip You may want to start with a clean 6.0 configuration file from either our provided docker-compose.yml
example, or the flowcoll.conf
file in the native packages. You can then provide only the modifications necessary to add to the new configuration. :::
Licensing Options
Logging Options
The only change is that FLOW_
has been removed from the option names.
Metrics Options
Flow UDP Server Options
AWS VPC Flow Logs Options
Decoding Options
Application Enrichment Options
:::danger While the configuration options for IP/port to application attributes enrichment are renamed, the format of the file pointed to by EF_PROCESSOR_ENRICH_APP_IPPORT_PATH
has changed significantly. Please refer to the configuration reference page for an example. :::
IP Address Enrichment Options
The primary change is that FLOW_DECODER
has been renamed to PROCESSOR
in the option names.
Network Interface Enrichment Options
The only change is that FLOW_DECODER
has been renamed to PROCESSOR
in the option names.
Post-Processing Enrichment Options
stdout Output Options
The only change is that FLOW_
has been removed from the option names.
Monitor Output Options
The only change is that FLOW_
has been removed from the option names.
Elasticsearch Output Options
The primary change is that FLOW_
has been removed from the option names. A few options have been removed.
OpenSearch Output Options
The primary change is that FLOW_
has been removed from the option names.
Splunk Output Options
The only change is that FLOW_
has been removed from the option names.
Kafka Output Options
The primary change is that FLOW_
has been removed from the option names.
Cribl Stream Output Options
The only change is that FLOW_
has been removed from the option names.
Generic HTTP Output Options
RiskIQ Output Options
The only change is that FLOW_
has been removed from the option names.