Flow Logs
- Capture IP TrafficandNetworkinformation
- Help monitor and troubleshoot connectivity issues
- Can be used for
- VPClevel
- SubnetLevel
- Elastic Network Interfacelevel
- Store logs in S3/Cloudwatch Logs
- Can query the logs using
- Athenain- S3logs
- Cloudwatch Log Insightsin- Cloudwatch Logs
- Can not enable Flow LogsofVPCthat is Peered and belongs toAnother Account
- After creating a flow log, configuration can not be changed
- For example, can not change IAM Roles
- Following IP Trafficdoes not monitor
- AWS DNS server
- Traffic of Windows Instanceactivating licence
- Traffic of Instance Metadata(169.254.169.254)
- DHCP traffic
- Reserved IP Addressof- Default VPC Router