Configuration Changes

To improve the consistency of configuration options and prepare for future features on ElastiFlow's roadmap, many of the configuration options have been renamed or otherwise changed. The following is a list of all changes.

:::tip You may want to start with a clean 6.0 configuration file from either our provided docker-compose.yml example, or the flowcoll.conf file in the native packages. You can then provide only the modifications necessary to add to the new configuration. :::

Licensing Options

Logging Options

The only change is that FLOW_ has been removed from the option names.

Metrics Options

Flow UDP Server Options

AWS VPC Flow Logs Options

Decoding Options

Application Enrichment Options

:::danger While the configuration options for IP/port to application attributes enrichment are renamed, the format of the file pointed to by EF_PROCESSOR_ENRICH_APP_IPPORT_PATH has changed significantly. Please refer to the configuration reference page for an example. :::

IP Address Enrichment Options

The primary change is that FLOW_DECODER has been renamed to PROCESSOR in the option names.

Network Interface Enrichment Options

The only change is that FLOW_DECODER has been renamed to PROCESSOR in the option names.

Post-Processing Enrichment Options

stdout Output Options

The only change is that FLOW_ has been removed from the option names.

Monitor Output Options

The only change is that FLOW_ has been removed from the option names.

Elasticsearch Output Options

The primary change is that FLOW_ has been removed from the option names. A few options have been removed.

OpenSearch Output Options

The primary change is that FLOW_ has been removed from the option names.

Splunk Output Options

The only change is that FLOW_ has been removed from the option names.

Kafka Output Options

The primary change is that FLOW_ has been removed from the option names.

Cribl Stream Output Options

The only change is that FLOW_ has been removed from the option names.

Generic HTTP Output Options

RiskIQ Output Options

The only change is that FLOW_ has been removed from the option names.