Enable VPC flow logs
- Navigate to VPC in the AWS console
data:image/s3,"s3://crabby-images/72732/72732c2226337d7b9a06b4dcc0e454c9079d84d3" alt=""
- Under Resources by Region Select VPCs
data:image/s3,"s3://crabby-images/d0f16/d0f1689bd54a22dc0285daf068955af5f06c6c0a" alt=""
- The next step will use the CloudShell, where you'll copy and paste a CLI command to more efficiently and accurately enable working flow log configuration for your VPC.
Flow logs will be enabled with the following settings preconfigured:
- Traffic type: ALL
- Resource ID:
- Log destination type: S3
- Max aggregation interval: 1 minute
- Open Cloudshell
You'll see a command prompt open up on the lower half of the screen
data:image/s3,"s3://crabby-images/0bef4/0bef477e71f500b38a2bd12dad88a2162338dc90" alt=""
- Copy and paste the command below, replace
<VPC ID>
with the VPC ID you want to enable flow logs for, and replace<bucket name>
with the name of your S3 bucket created in a previous step.
aws ec2 create-flow-logs \
--resource-type VPC \
--resource-ids <VPC ID> \
--traffic-type ALL \
--log-destination-type s3 \
--log-destination arn:aws:s3:::<bucket name> \
--log-format '${version} ${account-id} ${interface-id} ${srcaddr} ${dstaddr} ${srcport} ${dstport} ${protocol} ${packets} ${bytes} ${start} ${end} ${action} ${log-status} ${tcp-flags} ${type} ${pkt-dstaddr} ${pkt-srcaddr} ${instance-id} ${vpc-id} ${az-id} ${sublocation-id} ${sublocation-type} ${subnet-id}' \
--max-aggregation-interval 60
data:image/s3,"s3://crabby-images/a594c/a594c51e1d722682c367417612c19350448bf500" alt=""
If the log format isn't specified exactly as it is in the above command, your integration will fail.
- Once you've pasted in the command, it should look like this:
data:image/s3,"s3://crabby-images/f324d/f324d7188d497eb7effa24600bcbe57468e70617" alt=""
- Hit the enter key to run the command.
If you see the below, your flow logs have been successfully created.
"Unsuccessful":[]
means you were successful and no errors were indicated.
data:image/s3,"s3://crabby-images/b880e/b880eddeed01c5e5febae4796da5d6856b51b0f5" alt=""
Updated 4 months ago