Flow Logs
- Capture
IP Traffic
andNetwork
information - Help monitor and troubleshoot connectivity issues
- Can be used for
VPC
levelSubnet
LevelElastic Network Interface
level- Store logs in
S3
/Cloudwatch Logs
- Can query the logs using
Athena
inS3
logsCloudwatch Log Insights
inCloudwatch Logs
- Can not enable
Flow Logs
ofVPC
that is Peered and belongs toAnother Account
- After creating a flow log, configuration can not be changed
- For example, can not change
IAM Roles
- Following
IP Traffic
does not monitor - AWS DNS server
- Traffic of
Windows Instance
activating licence - Traffic of
Instance Metadata
(169.254.169.254) - DHCP traffic
Reserved IP Address
ofDefault VPC Router