VPC Flow Logs

E426154

VPC Flow Logs is an AWS feature that captures detailed information about IP traffic going to and from network interfaces in a Virtual Private Cloud for monitoring, troubleshooting, and security analysis.

All labels observed (1)

Label Occurrences
VPC Flow Logs canonical 1

How this entity was disambiguated

Statements (59)

Predicate Object
instanceOf AWS networking feature
cloud logging service feature
availableIn most AWS commercial regions
belongsToServiceCategory AWS networking and content delivery
canBeFilteredBy VPC
network interface
subnet
traffic type
captures IP traffic metadata
information about accepted traffic
information about all traffic (depending on configuration)
information about rejected traffic
developedBy Amazon Web Services
hasProperty can be enabled or disabled per resource
captures flow-level metadata only
does not capture packet payloads
generates charges based on log volume and destination service
integratesWith AWS CloudTrail (for auditing configuration changes)
linked to: AWS CloudTrail

AWS Lambda (for log processing)
linked to: AWS Lambda

AWS Security Hub
Amazon Athena (for querying logs in S3)
linked to: Amazon Athena

Amazon GuardDuty (as a data source)
linked to: Amazon GuardDuty

Amazon OpenSearch Service (via log streaming)
logsTo Amazon CloudWatch Logs
linked to: Amazon CloudWatch

Amazon S3
operatesOn Elastic Network Interfaces
VPC network interfaces
VPCs
subnets
partOf Amazon VPC
records VPC ID
action (ACCEPT or REJECT)
bytes count
destination IP address
destination port
end time of the flow
instance ID (when applicable)
interface ID
log status
packets count
protocol
source IP address
source port
start time of the flow
subnet ID
traffic direction
supports cross-account log delivery
custom fields selection (depending on version)
log aggregation in centralized accounts
multiple log formats
usedFor compliance reporting
network monitoring
network troubleshooting
security analysis
traffic visibility in Amazon VPC
usedTo analyze connectivity issues
detect anomalous traffic patterns
identify overly permissive security groups
validate network access controls

How these facts were elicited

Referenced by (1)

Full triples — surface form annotated when it differs from this entity's canonical label.

Amazon CloudWatch supports VPC Flow Logs