Skip to main content
Version: 6.3

Upgrading to 6.0

Configuration Changes

To improve the consistency of configuration options and prepare for future features on ElastiFlow's roadmap, many of the configuration options have been renamed or otherwise changed. The following is a list of all changes.

tip

You may want to start with a clean 6.0 configuration file from either our provided docker-compose.yml example, or the flowcoll.conf file in the native packages. You can then provide only the modifications necessary to add to the new configuration.

Licensing Options

5.6.x OptionStatusNotes for 6.0
___NEWEF_LICENSE_ACCEPTED
EF_FLOW_ACCOUNT_IDRENAMEDEF_ACCOUNT_ID
EF_FLOW_LICENSE_KEYUnchanged
EF_FLOW_LICENSED_UNITSUnchanged

Logging Options

The only change is that FLOW_ has been removed from the option names.

5.6.x OptionStatusNotes for 6.0
EF_FLOW_LOGGER_LEVELRENAMEDEF_LOGGER_LEVEL
EF_FLOW_LOGGER_ENCODINGRENAMEDEF_LOGGER_ENCODING
EF_FLOW_LOGGER_FILE_LOG_ENABLERENAMEDEF_LOGGER_FILE_LOG_ENABLE
EF_FLOW_LOGGER_FILE_LOG_FILENAMERENAMEDEF_LOGGER_FILE_LOG_FILENAME
EF_FLOW_LOGGER_FILE_LOG_MAX_SIZERENAMEDEF_LOGGER_FILE_LOG_MAX_SIZE
EF_FLOW_LOGGER_FILE_LOG_MAX_AGERENAMEDEF_LOGGER_FILE_LOG_MAX_AGE
EF_FLOW_LOGGER_FILE_LOG_MAX_BACKUPSRENAMEDEF_LOGGER_FILE_LOG_MAX_BACKUPS
EF_FLOW_LOGGER_FILE_LOG_COMPRESSRENAMEDEF_LOGGER_FILE_LOG_COMPRESS

Metrics Options

5.6.x OptionStatusNotes for 6.0
___NEWEF_INSTANCE_NAME
___NEWEF_METRICS_PORT
___NEWEF_METRICS_TLS_ENABLE
___NEWEF_METRICS_TLS_CERT_FILEPATH
___NEWEF_METRICS_TLS_KEY_FILEPATH

Flow UDP Server Options

5.6.x OptionStatusNotes for 6.0
EF_FLOW_SERVER_UDP_IPUnchanged
EF_FLOW_SERVER_UDP_PORTUnchanged
EF_FLOW_SERVER_UDP_READ_BUFFER_MAX_SIZEUnchanged
EF_FLOW_SERVER_UDP_PACKET_STREAM_MAX_SIZERENAMEDEF_FLOW_PACKET_STREAM_MAX_SIZE

AWS VPC Flow Logs Options

5.6.x OptionStatusNotes for 6.0
___NEWEF_AWS_VPC_FLOW_LOG_ENABLE
___NEWEF_AWS_VPC_FLOW_LOG_S3_BUCKET
___NEWEF_AWS_VPC_FLOW_LOG_PREFIX
___NEWAWS_REGION
___NEWAWS_ACCESS_KEY_ID
___NEWAWS_SECRET_ACCESS_KEY

Decoding Options

5.6.x OptionStatusNotes for 6.0
EF_FLOW_DECODER_POOL_SIZERENAMEDEF_PROCESSOR_POOL_SIZE
EF_FLOW_DECODER_SETTINGS_PATHREMOVED: Absolute paths MUST now be used for all option values that define a path to a file or directory.
EF_FLOW_DECODER_IPFIX_ENABLERENAMEDEF_PROCESSOR_DECODE_IPFIX_ENABLE
EF_FLOW_DECODER_NETFLOW1_ENABLERENAMEDEF_PROCESSOR_DECODE_NETFLOW1_ENABLE
EF_FLOW_DECODER_NETFLOW5_ENABLERENAMEDEF_PROCESSOR_DECODE_NETFLOW5_ENABLE
EF_FLOW_DECODER_NETFLOW6_ENABLERENAMEDEF_PROCESSOR_DECODE_NETFLOW6_ENABLE
EF_FLOW_DECODER_NETFLOW7_ENABLERENAMEDEF_PROCESSOR_DECODE_NETFLOW7_ENABLE
EF_FLOW_DECODER_NETFLOW9_ENABLERENAMEDEF_PROCESSOR_DECODE_NETFLOW9_ENABLE
EF_FLOW_DECODER_SFLOW5_ENABLERENAMEDEF_PROCESSOR_DECODE_SFLOW5_ENABLE
EF_FLOW_DECODER_SFLOW_FLOWS_ENABLERENAMEDEF_PROCESSOR_DECODE_SFLOW_FLOWS_ENABLE
EF_FLOW_DECODER_SFLOW_FLOWS_KEEP_SAMPLESRENAMEDEF_PROCESSOR_DECODE_SFLOW_FLOWS_KEEP_SAMPLES
EF_FLOW_DECODER_SFLOW_COUNTERS_ENABLERENAMEDEF_PROCESSOR_DECODE_SFLOW_COUNTERS_ENABLE
EF_FLOW_DECODER_TRANSLATE_KEEP_IDSRENAMEDEF_PROCESSOR_TRANSLATE_KEEP_IDS

Application Enrichment Options

5.6.x OptionStatusNotes for 6.0
___NEWEF_PROCESSOR_ENRICH_APP_ID_ENABLE
___NEWEF_PROCESSOR_ENRICH_APP_ID_PATH
___NEWEF_PROCESSOR_ENRICH_APP_ID_TTL
EF_FLOW_DECODER_ENRICH_APP_CACHE_SIZEREMOVED: TTL is now used to flush old cache entries.
EF_FLOW_DECODER_ENRICH_APP_USERDEF_ENABLERENAMEDEF_PROCESSOR_ENRICH_APP_IPPORT_ENABLE
EF_FLOW_DECODER_ENRICH_APP_USERDEF_PRIVATERENAMEDEF_PROCESSOR_ENRICH_APP_IPPORT_PRIVATE
EF_FLOW_DECODER_ENRICH_APP_USERDEF_PUBLICRENAMEDEF_PROCESSOR_ENRICH_APP_IPPORT_PUBLIC
EF_FLOW_DECODER_ENRICH_APP_USERDEF_PATHRENAMEDEF_PROCESSOR_ENRICH_APP_IPPORT_PATH
___NEWEF_PROCESSOR_ENRICH_APP_IPPORT_TTL
___NEWEF_PROCESSOR_ENRICH_APP_REFRESH_RATE
danger

While the configuration options for IP/port to application attributes enrichment are renamed, the format of the file pointed to by EF_PROCESSOR_ENRICH_APP_IPPORT_PATH has changed significantly. Please refer to the configuration reference page for an example.

IP Address Enrichment Options

The primary change is that FLOW_DECODER has been renamed to PROCESSOR in the option names.

5.6.x OptionStatusNotes for 6.0
___NEWEF_PROCESSOR_ENRICH_OPTION_ENUM_TTL
EF_FLOW_DECODER_ENRICH_IPADDR_TTLRENAMEDEF_PROCESSOR_ENRICH_IPADDR_TTL
EF_FLOW_DECODER_ENRICH_IPADDR_METADATA_ENABLERENAMEDEF_PROCESSOR_ENRICH_IPADDR_METADATA_ENABLE
EF_FLOW_DECODER_ENRICH_IPADDR_METADATA_USERDEF_PATHRENAMEDEF_PROCESSOR_ENRICH_IPADDR_METADATA_USERDEF_PATH
EF_FLOW_DECODER_ENRICH_IPADDR_METADATA_REFRESH_RATERENAMEDEF_PROCESSOR_ENRICH_IPADDR_METADATA_REFRESH_RATE
EF_FLOW_DECODER_ENRICH_DNS_ENABLERENAMEDEF_PROCESSOR_ENRICH_IPADDR_DNS_ENABLE
EF_FLOW_DECODER_ENRICH_DNS_NAMESERVER_IPRENAMEDEF_PROCESSOR_ENRICH_IPADDR_DNS_NAMESERVER_IP
EF_FLOW_DECODER_ENRICH_DNS_NAMESERVER_TIMEOUTRENAMEDEF_PROCESSOR_ENRICH_IPADDR_DNS_NAMESERVER_TIMEOUT
EF_FLOW_DECODER_ENRICH_DNS_RESOLVE_PRIVATERENAMEDEF_PROCESSOR_ENRICH_IPADDR_DNS_RESOLVE_PRIVATE
EF_FLOW_DECODER_ENRICH_DNS_RESOLVE_PUBLICRENAMEDEF_PROCESSOR_ENRICH_IPADDR_DNS_RESOLVE_PUBLIC
EF_FLOW_DECODER_ENRICH_DNS_USERDEF_PATHRENAMEDEF_PROCESSOR_ENRICH_IPADDR_DNS_USERDEF_PATH
EF_FLOW_DECODER_ENRICH_DNS_USERDEF_REFRESH_RATERENAMEDEF_PROCESSOR_ENRICH_IPADDR_DNS_USERDEF_REFRESH_RATE
EF_FLOW_DECODER_ENRICH_DNS_INCLEXCL_PATHRENAMEDEF_PROCESSOR_ENRICH_IPADDR_DNS_INCLEXCL_PATH
EF_FLOW_DECODER_ENRICH_DNS_INCLEXCL_REFRESH_RATERENAMEDEF_PROCESSOR_ENRICH_IPADDR_DNS_INCLEXCL_REFRESH_RATE
EF_FLOW_DECODER_ENRICH_MAXMIND_ASN_ENABLERENAMEDEF_PROCESSOR_ENRICH_IPADDR_MAXMIND_ASN_ENABLE
EF_FLOW_DECODER_ENRICH_MAXMIND_ASN_PATHRENAMEDEF_PROCESSOR_ENRICH_IPADDR_MAXMIND_ASN_PATH
EF_FLOW_DECODER_ENRICH_MAXMIND_GEOIP_ENABLERENAMEDEF_PROCESSOR_ENRICH_IPADDR_MAXMIND_GEOIP_ENABLE
EF_FLOW_DECODER_ENRICH_MAXMIND_GEOIP_PATHRENAMEDEF_PROCESSOR_ENRICH_IPADDR_MAXMIND_GEOIP_PATH
EF_FLOW_DECODER_ENRICH_MAXMIND_GEOIP_VALUESRENAMEDEF_PROCESSOR_ENRICH_IPADDR_MAXMIND_GEOIP_VALUES
EF_FLOW_DECODER_ENRICH_MAXMIND_GEOIP_LANGRENAMEDEF_PROCESSOR_ENRICH_IPADDR_MAXMIND_GEOIP_LANG
EF_FLOW_DECODER_ENRICH_MAXMIND_GEOIP_INCLEXCL_PATHRENAMEDEF_PROCESSOR_ENRICH_IPADDR_MAXMIND_GEOIP_INCLEXCL_PATH
EF_FLOW_DECODER_ENRICH_MAXMIND_GEOIP_INCLEXCL_REFRESH_RATERENAMEDEF_PROCESSOR_ENRICH_IPADDR_MAXMIND_GEOIP_INCLEXCL_REFRESH_RATE
EF_FLOW_DECODER_ENRICH_RISKIQ_THREAT_ENABLERENAMEDEF_PROCESSOR_ENRICH_IPADDR_RISKIQ_THREAT_ENABLE
EF_FLOW_DECODER_ENRICH_RISKIQ_THREAT_ENDPOINTRENAMEDEF_PROCESSOR_ENRICH_IPADDR_RISKIQ_THREAT_ENDPOINT
EF_FLOW_DECODER_ENRICH_RISKIQ_THREAT_REFRESH_INTERVALRENAMEDEF_PROCESSOR_ENRICH_IPADDR_RISKIQ_THREAT_REFRESH_INTERVAL
EF_FLOW_DECODER_ENRICH_RISKIQ_THREAT_INCLEXCL_PATHRENAMEDEF_PROCESSOR_ENRICH_IPADDR_RISKIQ_THREAT_INCLEXCL_PATH
EF_FLOW_DECODER_ENRICH_RISKIQ_THREAT_INCLEXCL_REFRESH_RATERENAMEDEF_PROCESSOR_ENRICH_IPADDR_RISKIQ_THREAT_INCLEXCL_REFRESH_RATE
EF_FLOW_DECODER_ENRICH_RISKIQ_API_USERRENAMEDEF_PROCESSOR_ENRICH_IPADDR_RISKIQ_API_USER
EF_FLOW_DECODER_ENRICH_RISKIQ_API_KEYRENAMEDEF_PROCESSOR_ENRICH_IPADDR_RISKIQ_API_KEY
EF_FLOW_DECODER_ENRICH_RISKIQ_API_TIMEOUTRENAMEDEF_PROCESSOR_ENRICH_IPADDR_RISKIQ_API_TIMEOUT
EF_FLOW_DECODER_ENRICH_ASN_PREFRENAMEDEF_PROCESSOR_ENRICH_ASN_PREF

Network Interface Enrichment Options

The only change is that FLOW_DECODER has been renamed to PROCESSOR in the option names.

5.6.x OptionStatusNotes for 6.0
EF_FLOW_DECODER_ENRICH_NETIF_TTLRENAMEDEF_PROCESSOR_ENRICH_NETIF_TTL
EF_FLOW_DECODER_ENRICH_NETIF_METADATA_ENABLERENAMEDEF_PROCESSOR_ENRICH_NETIF_METADATA_ENABLE
EF_FLOW_DECODER_ENRICH_NETIF_METADATA_USERDEF_PATHRENAMEDEF_PROCESSOR_ENRICH_NETIF_METADATA_USERDEF_PATH
EF_FLOW_DECODER_ENRICH_NETIF_METADATA_REFRESH_RATERENAMEDEF_PROCESSOR_ENRICH_NETIF_METADATA_REFRESH_RATE
EF_FLOW_DECODER_ENRICH_NETIF_FLOW_OPTIONS_ENABLERENAMEDEF_PROCESSOR_ENRICH_NETIF_FLOW_OPTIONS_ENABLE
EF_FLOW_DECODER_ENRICH_NETIF_SNMP_ENABLERENAMEDEF_PROCESSOR_ENRICH_NETIF_SNMP_ENABLE
EF_FLOW_DECODER_ENRICH_NETIF_SNMP_PORTRENAMEDEF_PROCESSOR_ENRICH_NETIF_SNMP_PORT
EF_FLOW_DECODER_ENRICH_NETIF_SNMP_VERSIONRENAMEDEF_PROCESSOR_ENRICH_NETIF_SNMP_VERSION
EF_FLOW_DECODER_ENRICH_NETIF_SNMP_COMMUNITIESRENAMEDEF_PROCESSOR_ENRICH_NETIF_SNMP_COMMUNITIES
EF_FLOW_DECODER_ENRICH_NETIF_SNMP_TIMEOUTRENAMEDEF_PROCESSOR_ENRICH_NETIF_SNMP_TIMEOUT
EF_FLOW_DECODER_ENRICH_NETIF_SNMP_RETRIESRENAMEDEF_PROCESSOR_ENRICH_NETIF_SNMP_RETRIES

Post-Processing Enrichment Options

5.6.x OptionStatusNotes for 6.0
EF_FLOW_DECODER_ENRICH_TOTALS_IF_NO_DELTASRENAMEDEF_PROCESSOR_ENRICH_TOTALS_IF_NO_DELTAS
EF_FLOW_DECODER_ENRICH_SAMPLERATE_CACHE_SIZERENAMEDEF_PROCESSOR_ENRICH_SAMPLERATE_CACHE_SIZE
EF_FLOW_DECODER_ENRICH_SAMPLERATE_USERDEF_ENABLERENAMEDEF_PROCESSOR_ENRICH_SAMPLERATE_USERDEF_ENABLE
EF_FLOW_DECODER_ENRICH_SAMPLERATE_USERDEF_PATHRENAMEDEF_PROCESSOR_ENRICH_SAMPLERATE_USERDEF_PATH
___NEWEF_PROCESSOR_ENRICH_SAMPLERATE_USERDEF_OVERRIDE
EF_FLOW_DECODER_ENRICH_COMMUNITYID_ENABLERENAMEDEF_PROCESSOR_ENRICH_COMMUNITYID_ENABLE
EF_FLOW_DECODER_ENRICH_COMMUNITYID_SEEDRENAMEDEF_PROCESSOR_ENRICH_COMMUNITYID_SEED
EF_FLOW_DECODER_ENRICH_CONVERSATIONID_ENABLERENAMEDEF_PROCESSOR_ENRICH_CONVERSATIONID_ENABLE
EF_FLOW_DECODER_ENRICH_CONVERSATIONID_SEEDRENAMEDEF_PROCESSOR_ENRICH_CONVERSATIONID_SEED
EF_FLOW_DECODER_ENRICH_JOIN_ASNRENAMEDEF_PROCESSOR_ENRICH_JOIN_ASN
EF_FLOW_DECODER_ENRICH_JOIN_GEOIPRENAMEDEF_PROCESSOR_ENRICH_JOIN_GEOIP
EF_FLOW_DECODER_ENRICH_JOIN_SECRENAMEDEF_PROCESSOR_ENRICH_JOIN_SEC
EF_FLOW_DECODER_ENRICH_JOIN_NETATTRRENAMEDEF_PROCESSOR_ENRICH_JOIN_NETATTR
EF_FLOW_DECODER_ENRICH_JOIN_SUBNETATTRRENAMEDEF_PROCESSOR_ENRICH_JOIN_SUBNETATTR
EF_FLOW_DECODER_DURATION_PRECISIONRENAMEDEF_PROCESSOR_DURATION_PRECISION
EF_FLOW_DECODER_TIMESTAMP_PRECISIONRENAMEDEF_PROCESSOR_TIMESTAMP_PRECISION
EF_FLOW_DECODER_PERCENT_NORMRENAMEDEF_PROCESSOR_PERCENT_NORM
EF_FLOW_DECODER_ENRICH_EXPAND_CLISRVRENAMEDEF_PROCESSOR_EXPAND_CLISRV
___NEWEF_PROCESSOR_EXPAND_CLISRV_NO_L4_PORTS
EF_FLOW_DECODER_ENRICH_KEEP_CPU_TICKSRENAMEDEF_PROCESSOR_KEEP_CPU_TICKS
EF_FLOW_DECODER_ENRICH_DROP_FIELDSRENAMEDEF_PROCESSOR_DROP_FIELDS
EF_FLOW_RECORD_STREAM_MAX_SIZEREMOVED: The record stream size has been optimized for peak performance and requires no adjustment.

stdout Output Options

The only change is that FLOW_ has been removed from the option names.

5.6.x OptionStatusNotes for 6.0
EF_FLOW_OUTPUT_STDOUT_ENABLERENAMEDEF_OUTPUT_STDOUT_ENABLE
EF_FLOW_OUTPUT_STDOUT_FORMATRENAMEDEF_OUTPUT_STDOUT_FORMAT

Monitor Output Options

The only change is that FLOW_ has been removed from the option names.

5.6.x OptionStatusNotes for 6.0
EF_FLOW_OUTPUT_MONITOR_ENABLERENAMEDEF_OUTPUT_MONITOR_ENABLE
EF_FLOW_OUTPUT_MONITOR_INTERVALRENAMEDEF_OUTPUT_MONITOR_INTERVAL

Elasticsearch Output Options

The primary change is that FLOW_ has been removed from the option names. A few options have been removed.

5.6.x OptionStatusNotes for 6.0
EF_FLOW_OUTPUT_ELASTICSEARCH_ENABLERENAMEDEF_OUTPUT_ELASTICSEARCH_ENABLE
EF_FLOW_OUTPUT_ELASTICSEARCH_ECS_ENABLERENAMEDEF_OUTPUT_ELASTICSEARCH_ECS_ENABLE
EF_FLOW_OUTPUT_ELASTICSEARCH_BATCH_DEADLINERENAMEDEF_OUTPUT_ELASTICSEARCH_BATCH_DEADLINE
EF_FLOW_OUTPUT_ELASTICSEARCH_BATCH_MAX_BYTESRENAMEDEF_OUTPUT_ELASTICSEARCH_BATCH_MAX_BYTES
EF_FLOW_OUTPUT_ELASTICSEARCH_TIMESTAMP_SOURCERENAMEDEF_OUTPUT_ELASTICSEARCH_TIMESTAMP_SOURCE
EF_FLOW_OUTPUT_ELASTICSEARCH_INDEX_PERIODRENAMEDEF_OUTPUT_ELASTICSEARCH_INDEX_PERIOD
EF_FLOW_OUTPUT_ELASTICSEARCH_INDEX_SUFFIXRENAMEDEF_OUTPUT_ELASTICSEARCH_INDEX_SUFFIX
EF_FLOW_OUTPUT_ELASTICSEARCH_DROP_FIELDSRENAMEDEF_OUTPUT_ELASTICSEARCH_DROP_FIELDS
EF_FLOW_OUTPUT_ELASTICSEARCH_INDEX_TEMPLATE_ENABLERENAMEDEF_OUTPUT_ELASTICSEARCH_INDEX_TEMPLATE_ENABLE
EF_FLOW_OUTPUT_ELASTICSEARCH_INDEX_TEMPLATE_OVERWRITERENAMEDEF_OUTPUT_ELASTICSEARCH_INDEX_TEMPLATE_OVERWRITE
EF_FLOW_OUTPUT_ELASTICSEARCH_INDEX_TEMPLATE_SHARDSRENAMEDEF_OUTPUT_ELASTICSEARCH_INDEX_TEMPLATE_SHARDS
EF_FLOW_OUTPUT_ELASTICSEARCH_INDEX_TEMPLATE_REPLICASRENAMEDEF_OUTPUT_ELASTICSEARCH_INDEX_TEMPLATE_REPLICAS
EF_FLOW_OUTPUT_ELASTICSEARCH_INDEX_TEMPLATE_REFRESH_INTERVALRENAMEDEF_OUTPUT_ELASTICSEARCH_INDEX_TEMPLATE_REFRESH_INTERVAL
EF_FLOW_OUTPUT_ELASTICSEARCH_INDEX_TEMPLATE_CODECRENAMEDEF_OUTPUT_ELASTICSEARCH_INDEX_TEMPLATE_CODEC
EF_FLOW_OUTPUT_ELASTICSEARCH_INDEX_TEMPLATE_ILM_LIFECYCLERENAMEDEF_OUTPUT_ELASTICSEARCH_INDEX_TEMPLATE_ILM_LIFECYCLE
EF_FLOW_OUTPUT_ELASTICSEARCH_INDEX_TEMPLATE_ILM_ROLLOVER_ALIASREMOVED: The rollover alias is generated automatically by the collector.
EF_FLOW_OUTPUT_ELASTICSEARCH_INDEX_TEMPLATE_ISM_POLICYREMOVED: The Elasticsearch output no longer supports OpenSearch-specific features.
EF_FLOW_OUTPUT_ELASTICSEARCH_INDEX_PIPELINE_DEFAULTRENAMEDEF_OUTPUT_ELASTICSEARCH_INDEX_TEMPLATE_PIPELINE_DEFAULT
EF_FLOW_OUTPUT_ELASTICSEARCH_INDEX_PIPELINE_FINALRENAMEDEF_OUTPUT_ELASTICSEARCH_INDEX_TEMPLATE_PIPELINE_FINAL
EF_FLOW_OUTPUT_ELASTICSEARCH_ADDRESSESRENAMEDEF_OUTPUT_ELASTICSEARCH_ADDRESSES
EF_FLOW_OUTPUT_ELASTICSEARCH_USERNAMERENAMEDEF_OUTPUT_ELASTICSEARCH_USERNAME
EF_FLOW_OUTPUT_ELASTICSEARCH_PASSWORDRENAMEDEF_OUTPUT_ELASTICSEARCH_PASSWORD
EF_FLOW_OUTPUT_ELASTICSEARCH_CLOUD_IDRENAMEDEF_OUTPUT_ELASTICSEARCH_CLOUD_ID
EF_FLOW_OUTPUT_ELASTICSEARCH_API_KEYRENAMEDEF_OUTPUT_ELASTICSEARCH_API_KEY
EF_FLOW_OUTPUT_ELASTICSEARCH_CLIENT_CA_CERT_FILEPATHRENAMEDEF_OUTPUT_ELASTICSEARCH_CLIENT_CA_CERT_FILEPATH
EF_FLOW_OUTPUT_ELASTICSEARCH_CLIENT_CERT_FILEPATHRENAMEDEF_OUTPUT_ELASTICSEARCH_CLIENT_CERT_FILEPATH
EF_FLOW_OUTPUT_ELASTICSEARCH_CLIENT_KEY_FILEPATHRENAMEDEF_OUTPUT_ELASTICSEARCH_CLIENT_KEY_FILEPATH
EF_FLOW_OUTPUT_ELASTICSEARCH_TLS_ENABLERENAMEDEF_OUTPUT_ELASTICSEARCH_TLS_ENABLE
EF_FLOW_OUTPUT_ELASTICSEARCH_TLS_SKIP_VERIFICATIONRENAMEDEF_OUTPUT_ELASTICSEARCH_TLS_SKIP_VERIFICATION
EF_FLOW_OUTPUT_ELASTICSEARCH_TLS_CA_CERT_FILEPATHRENAMEDEF_OUTPUT_ELASTICSEARCH_TLS_CA_CERT_FILEPATH
EF_FLOW_OUTPUT_ELASTICSEARCH_RETRY_ENABLERENAMEDEF_OUTPUT_ELASTICSEARCH_RETRY_ENABLE
EF_FLOW_OUTPUT_ELASTICSEARCH_RETRY_ON_TIMEOUT_ENABLERENAMEDEF_OUTPUT_ELASTICSEARCH_RETRY_ON_TIMEOUT_ENABLE
EF_FLOW_OUTPUT_ELASTICSEARCH_MAX_RETRIESRENAMEDEF_OUTPUT_ELASTICSEARCH_MAX_RETRIES
EF_FLOW_OUTPUT_ELASTICSEARCH_RETRY_BACKOFFRENAMEDEF_OUTPUT_ELASTICSEARCH_RETRY_BACKOFF
___NEWEF_OUTPUT_ELASTICSEARCH_ALLOWED_RECORD_TYPES

OpenSearch Output Options

The primary change is that FLOW_ has been removed from the option names.

5.6.x OptionStatusNotes for 6.0
EF_FLOW_OUTPUT_OPENSEARCH_ENABLERENAMEDEF_OUTPUT_OPENSEARCH_ENABLE
EF_FLOW_OUTPUT_OPENSEARCH_ECS_ENABLERENAMEDEF_OUTPUT_OPENSEARCH_ECS_ENABLE
EF_FLOW_OUTPUT_OPENSEARCH_BATCH_DEADLINERENAMEDEF_OUTPUT_OPENSEARCH_BATCH_DEADLINE
EF_FLOW_OUTPUT_OPENSEARCH_BATCH_MAX_BYTESRENAMEDEF_OUTPUT_OPENSEARCH_BATCH_MAX_BYTES
EF_FLOW_OUTPUT_OPENSEARCH_TIMESTAMP_SOURCERENAMEDEF_OUTPUT_OPENSEARCH_TIMESTAMP_SOURCE
EF_FLOW_OUTPUT_OPENSEARCH_INDEX_PERIODRENAMEDEF_OUTPUT_OPENSEARCH_INDEX_PERIOD
EF_FLOW_OUTPUT_OPENSEARCH_INDEX_SUFFIXRENAMEDEF_OUTPUT_OPENSEARCH_INDEX_SUFFIX
EF_FLOW_OUTPUT_OPENSEARCH_DROP_FIELDSRENAMEDEF_OUTPUT_OPENSEARCH_DROP_FIELDS
EF_FLOW_OUTPUT_OPENSEARCH_INDEX_TEMPLATE_ENABLERENAMEDEF_OUTPUT_OPENSEARCH_INDEX_TEMPLATE_ENABLE
EF_FLOW_OUTPUT_OPENSEARCH_INDEX_TEMPLATE_OVERWRITERENAMEDEF_OUTPUT_OPENSEARCH_INDEX_TEMPLATE_OVERWRITE
EF_FLOW_OUTPUT_OPENSEARCH_INDEX_TEMPLATE_SHARDSRENAMEDEF_OUTPUT_OPENSEARCH_INDEX_TEMPLATE_SHARDS
EF_FLOW_OUTPUT_OPENSEARCH_INDEX_TEMPLATE_REPLICASRENAMEDEF_OUTPUT_OPENSEARCH_INDEX_TEMPLATE_REPLICAS
EF_FLOW_OUTPUT_OPENSEARCH_INDEX_TEMPLATE_REFRESH_INTERVALRENAMEDEF_OUTPUT_OPENSEARCH_INDEX_TEMPLATE_REFRESH_INTERVAL
EF_FLOW_OUTPUT_OPENSEARCH_INDEX_TEMPLATE_CODECRENAMEDEF_OUTPUT_OPENSEARCH_INDEX_TEMPLATE_CODEC
EF_FLOW_OUTPUT_OPENSEARCH_INDEX_TEMPLATE_ISM_POLICYRENAMEDEF_OUTPUT_OPENSEARCH_INDEX_TEMPLATE_ISM_POLICY
EF_FLOW_OUTPUT_OPENSEARCH_INDEX_TEMPLATE_PIPELINE_DEFAULTRENAMEDEF_OUTPUT_OPENSEARCH_INDEX_TEMPLATE_PIPELINE_DEFAULT
EF_FLOW_OUTPUT_OPENSEARCH_INDEX_TEMPLATE_PIPELINE_FINALRENAMEDEF_OUTPUT_OPENSEARCH_INDEX_TEMPLATE_PIPELINE_FINAL
EF_FLOW_OUTPUT_OPENSEARCH_ADDRESSESRENAMEDEF_OUTPUT_OPENSEARCH_ADDRESSES
EF_FLOW_OUTPUT_OPENSEARCH_USERNAMERENAMEDEF_OUTPUT_OPENSEARCH_USERNAME
EF_FLOW_OUTPUT_OPENSEARCH_PASSWORDRENAMEDEF_OUTPUT_OPENSEARCH_PASSWORD
EF_FLOW_OUTPUT_OPENSEARCH_CLIENT_CA_CERT_FILEPATHRENAMEDEF_OUTPUT_OPENSEARCH_CLIENT_CA_CERT_FILEPATH
EF_FLOW_OUTPUT_OPENSEARCH_CLIENT_CERT_FILEPATHRENAMEDEF_OUTPUT_OPENSEARCH_CLIENT_CERT_FILEPATH
EF_FLOW_OUTPUT_OPENSEARCH_CLIENT_KEY_FILEPATHRENAMEDEF_OUTPUT_OPENSEARCH_CLIENT_KEY_FILEPATH
EF_FLOW_OUTPUT_OPENSEARCH_TLS_ENABLERENAMEDEF_OUTPUT_OPENSEARCH_TLS_ENABLE
EF_FLOW_OUTPUT_OPENSEARCH_TLS_SKIP_VERIFICATIONRENAMEDEF_OUTPUT_OPENSEARCH_TLS_SKIP_VERIFICATION
EF_FLOW_OUTPUT_OPENSEARCH_TLS_CA_CERT_FILEPATHRENAMEDEF_OUTPUT_OPENSEARCH_TLS_CA_CERT_FILEPATH
EF_FLOW_OUTPUT_OPENSEARCH_RETRY_ENABLERENAMEDEF_OUTPUT_OPENSEARCH_RETRY_ENABLE
EF_FLOW_OUTPUT_OPENSEARCH_RETRY_ON_TIMEOUT_ENABLERENAMEDEF_OUTPUT_OPENSEARCH_RETRY_ON_TIMEOUT_ENABLE
EF_FLOW_OUTPUT_OPENSEARCH_MAX_RETRIESRENAMEDEF_OUTPUT_OPENSEARCH_MAX_RETRIES
EF_FLOW_OUTPUT_OPENSEARCH_RETRY_BACKOFFRENAMEDEF_OUTPUT_OPENSEARCH_RETRY_BACKOFF
___NEWEF_OUTPUT_OPENSEARCH_ALLOWED_RECORD_TYPES

Splunk Output Options

The only change is that FLOW_ has been removed from the option names.

5.6.x OptionStatusNotes for 6.0
EF_FLOW_OUTPUT_SPLUNK_HEC_ENABLERENAMEDEF_OUTPUT_SPLUNK_HEC_ENABLE
EF_FLOW_OUTPUT_SPLUNK_HEC_CIM_ENABLERENAMEDEF_OUTPUT_SPLUNK_HEC_CIM_ENABLE
EF_FLOW_OUTPUT_SPLUNK_HEC_ADDRESSESRENAMEDEF_OUTPUT_SPLUNK_HEC_ADDRESSES
EF_FLOW_OUTPUT_SPLUNK_HEC_TOKENRENAMEDEF_OUTPUT_SPLUNK_HEC_TOKEN
EF_FLOW_OUTPUT_SPLUNK_HEC_BATCH_MAX_BYTESRENAMEDEF_OUTPUT_SPLUNK_HEC_BATCH_MAX_BYTES
EF_FLOW_OUTPUT_SPLUNK_HEC_BATCH_DEADLINERENAMEDEF_OUTPUT_SPLUNK_HEC_BATCH_DEADLINE
EF_FLOW_OUTPUT_SPLUNK_HEC_TLS_ENABLERENAMEDEF_OUTPUT_SPLUNK_HEC_TLS_ENABLE
EF_FLOW_OUTPUT_SPLUNK_HEC_TLS_SKIP_VERIFICATIONRENAMEDEF_OUTPUT_SPLUNK_HEC_TLS_SKIP_VERIFICATION
EF_FLOW_OUTPUT_SPLUNK_HEC_TLS_CA_CERT_FILEPATHRENAMEDEF_OUTPUT_SPLUNK_HEC_TLS_CA_CERT_FILEPATH
EF_FLOW_OUTPUT_SPLUNK_HEC_DROP_FIELDSRENAMEDEF_OUTPUT_SPLUNK_HEC_DROP_FIELDS

Kafka Output Options

The primary change is that FLOW_ has been removed from the option names.

5.6.x OptionStatusNotes for 6.0
EF_FLOW_OUTPUT_KAFKA_ENABLERENAMEDEF_OUTPUT_KAFKA_ENABLE
EF_FLOW_OUTPUT_KAFKA_BROKERSRENAMEDEF_OUTPUT_KAFKA_BROKERS
EF_FLOW_OUTPUT_KAFKA_VERSIONRENAMEDEF_OUTPUT_KAFKA_VERSION
EF_FLOW_OUTPUT_KAFKA_TOPICRENAMEDEF_OUTPUT_KAFKA_TOPIC
EF_FLOW_OUTPUT_KAFKA_CLIENT_IDRENAMEDEF_OUTPUT_KAFKA_CLIENT_ID
EF_FLOW_OUTPUT_KAFKA_PARTITION_KEYRENAMEDEF_OUTPUT_KAFKA_PARTITION_KEY
EF_FLOW_OUTPUT_KAFKA_RACK_IDRENAMEDEF_OUTPUT_KAFKA_RACK_ID
EF_FLOW_OUTPUT_KAFKA_TIMEOUTRENAMEDEF_OUTPUT_KAFKA_TIMEOUT
EF_FLOW_OUTPUT_KAFKA_SASL_ENABLERENAMEDEF_OUTPUT_KAFKA_SASL_ENABLE
EF_FLOW_OUTPUT_KAFKA_SASL_USERNAMERENAMEDEF_OUTPUT_KAFKA_SASL_USERNAME
EF_FLOW_OUTPUT_KAFKA_SASL_PASSWORDRENAMEDEF_OUTPUT_KAFKA_SASL_PASSWORD
EF_FLOW_OUTPUT_KAFKA_TLS_ENABLERENAMEDEF_OUTPUT_KAFKA_TLS_ENABLE
EF_FLOW_OUTPUT_KAFKA_TLS_CA_CERT_FILEPATHRENAMEDEF_OUTPUT_KAFKA_TLS_CA_CERT_FILEPATH
EF_FLOW_OUTPUT_KAFKA_TLS_CERT_FILEPATHRENAMEDEF_OUTPUT_KAFKA_TLS_CERT_FILEPATH
EF_FLOW_OUTPUT_KAFKA_TLS_KEY_FILEPATHRENAMEDEF_OUTPUT_KAFKA_TLS_KEY_FILEPATH
EF_FLOW_OUTPUT_KAFKA_TLS_SKIP_VERIFICATIONRENAMEDEF_OUTPUT_KAFKA_TLS_SKIP_VERIFICATION
EF_FLOW_OUTPUT_KAFKA_PRODUCER_MAX_MESSAGE_BYTESRENAMEDEF_OUTPUT_KAFKA_PRODUCER_MAX_MESSAGE_BYTES
EF_FLOW_OUTPUT_KAFKA_PRODUCER_REQUIRED_ACKSRENAMEDEF_OUTPUT_KAFKA_PRODUCER_REQUIRED_ACKS
EF_FLOW_OUTPUT_KAFKA_PRODUCER_TIMEOUTRENAMEDEF_OUTPUT_KAFKA_PRODUCER_TIMEOUT
EF_FLOW_OUTPUT_KAFKA_PRODUCER_COMPRESSIONRENAMEDEF_OUTPUT_KAFKA_PRODUCER_COMPRESSION
EF_FLOW_OUTPUT_KAFKA_PRODUCER_COMPRESSION_LEVELRENAMEDEF_OUTPUT_KAFKA_PRODUCER_COMPRESSION_LEVEL
EF_FLOW_OUTPUT_KAFKA_PRODUCER_FLUSH_BYTESRENAMEDEF_OUTPUT_KAFKA_PRODUCER_FLUSH_BYTES
EF_FLOW_OUTPUT_KAFKA_PRODUCER_FLUSH_MESSAGESRENAMEDEF_OUTPUT_KAFKA_PRODUCER_FLUSH_MESSAGES
EF_FLOW_OUTPUT_KAFKA_PRODUCER_FLUSH_FREQUENCYRENAMEDEF_OUTPUT_KAFKA_PRODUCER_FLUSH_FREQUENCY
EF_FLOW_OUTPUT_KAFKA_PRODUCER_FLUSH_MAX_MESSAGESRENAMEDEF_OUTPUT_KAFKA_PRODUCER_FLUSH_MAX_MESSAGES
EF_FLOW_OUTPUT_KAFKA_PRODUCER_RETRY_MAXRENAMEDEF_OUTPUT_KAFKA_PRODUCER_RETRY_MAX
EF_FLOW_OUTPUT_KAFKA_PRODUCER_RETRY_BACKOFFRENAMEDEF_OUTPUT_KAFKA_PRODUCER_RETRY_BACKOFF
EF_FLOW_OUTPUT_KAFKA_DROP_FIELDSRENAMEDEF_OUTPUT_KAFKA_DROP_FIELDS
___NEWEF_OUTPUT_KAFKA_ALLOWED_RECORD_TYPES

Cribl Stream Output Options

The only change is that FLOW_ has been removed from the option names.

5.6.x OptionStatusNotes for 6.0
EF_FLOW_OUTPUT_CRIBL_ENABLERENAMEDEF_OUTPUT_CRIBL_ENABLE
EF_FLOW_OUTPUT_CRIBL_ADDRESSESRENAMEDEF_OUTPUT_CRIBL_ADDRESSES
EF_FLOW_OUTPUT_CRIBL_TOKENRENAMEDEF_OUTPUT_CRIBL_TOKEN
EF_FLOW_OUTPUT_CRIBL_BATCH_DEADLINERENAMEDEF_OUTPUT_CRIBL_BATCH_DEADLINE
EF_FLOW_OUTPUT_CRIBL_BATCH_MAX_BYTESRENAMEDEF_OUTPUT_CRIBL_BATCH_MAX_BYTES
EF_FLOW_OUTPUT_CRIBL_TLS_ENABLERENAMEDEF_OUTPUT_CRIBL_TLS_ENABLE
EF_FLOW_OUTPUT_CRIBL_TLS_SKIP_VERIFICATIONRENAMEDEF_OUTPUT_CRIBL_TLS_SKIP_VERIFICATION
EF_FLOW_OUTPUT_CRIBL_TLS_CA_CERT_FILEPATHRENAMEDEF_OUTPUT_CRIBL_TLS_CA_CERT_FILEPATH
EF_FLOW_OUTPUT_CRIBL_DROP_FIELDSRENAMEDEF_OUTPUT_CRIBL_DROP_FIELDS

Generic HTTP Output Options

5.6.x OptionStatusNotes for 6.0
___NEWEF_FLOW_OUTPUT_GENERIC_HTTP_ENABLE
___NEWEF_FLOW_OUTPUT_GENERIC_HTTP_ECS_ENABLE
___NEWEF_FLOW_OUTPUT_GENERIC_HTTP_BATCH_DEADLINE
___NEWEF_FLOW_OUTPUT_GENERIC_HTTP_BATCH_MAX_BYTES
___NEWEF_FLOW_OUTPUT_GENERIC_HTTP_ADDRESSES
___NEWEF_FLOW_OUTPUT_GENERIC_HTTP_USERNAME
___NEWEF_FLOW_OUTPUT_GENERIC_HTTP_PASSWORD
___NEWEF_FLOW_OUTPUT_GENERIC_HTTP_TLS_ENABLE
___NEWEF_FLOW_OUTPUT_GENERIC_HTTP_TLS_SKIP_VERIFICATION
___NEWEF_FLOW_OUTPUT_GENERIC_HTTP_TLS_CA_CERT_FILEPATH
___NEWEF_FLOW_OUTPUT_GENERIC_HTTP_DROP_FIELDS
___NEWEF_FLOW_OUTPUT_GENERIC_HTTP_TIMESTAMP_SOURCE

RiskIQ Output Options

The only change is that FLOW_ has been removed from the option names.

5.6.x OptionStatusNotes for 6.0
EF_FLOW_OUTPUT_RISKIQ_ENABLERENAMEDEF_OUTPUT_RISKIQ_ENABLE
EF_FLOW_OUTPUT_RISKIQ_HOSTRENAMEDEF_OUTPUT_RISKIQ_HOST
EF_FLOW_OUTPUT_RISKIQ_PORTRENAMEDEF_OUTPUT_RISKIQ_PORT
EF_FLOW_OUTPUT_RISKIQ_CUSTOMER_UUIDRENAMEDEF_OUTPUT_RISKIQ_CUSTOMER_UUID
EF_FLOW_OUTPUT_RISKIQ_CUSTOMER_ENCRYPTION_KEYRENAMEDEF_OUTPUT_RISKIQ_CUSTOMER_ENCRYPTION_KEY