Flow Logs
- Capture
IP TrafficandNetworkinformation - Help monitor and troubleshoot connectivity issues
- Can be used for
VPClevelSubnetLevelElastic Network Interfacelevel- Store logs in
S3/Cloudwatch Logs - Can query the logs using
AthenainS3logsCloudwatch Log InsightsinCloudwatch Logs- Can not enable
Flow LogsofVPCthat is Peered and belongs toAnother Account - After creating a flow log, configuration can not be changed
- For example, can not change
IAM Roles - Following
IP Trafficdoes not monitor - AWS DNS server
- Traffic of
Windows Instanceactivating licence - Traffic of
Instance Metadata(169.254.169.254) - DHCP traffic
Reserved IP AddressofDefault VPC Router