Skip to content

VPC Flow Log

Captures IP traffic to/from network interfaces in a VPC.

network
category
12
settings
1
inputs
1
outputs
SettingTypeRequiredDefault
Resource type
Options: VPC, Subnet, Network interface, Transit gateway, TGW attachment
ChoiceVPC
Resource IDText
Traffic type
Options: Accepted, Rejected, All
ChoiceALL
Destination type
Options: CloudWatch Logs, S3, Kinesis Firehose
Choicecloud-watch-logs
Destination ARNText
IAM role ARN (CloudWatch)Text
Log format (custom)Text
Max aggregation interval (s)Number600
File format (S3)
Options: Plain text, Parquet
Choiceplain-text
Hive-compatible partitions (S3)Togglefalse
Per-hour partition (S3)Togglefalse
TagsKey–value
SocketDirectionAcceptsTerraform arg
Source (VPC / subnet / ENI)Inputaws.vpc, aws.subnetvpc_id
Log destinationOutputaws.s3, aws.cloudwatch-log-group, aws.kinesis-firehoselog_destination