0
1

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?

More than 1 year has passed since last update.

VPC Flow Logs

Last updated at Posted at 2022-09-30

特徴

inbund,outbundの通信をキャプチャする。
デフォルトでは無効
インターフェースレベルでキャプチャする。
ただしリアルタイムではない。

全てのIPトラフィックをキャプチャするわけではない。
取らない通信はAWS DNS Serverへの通信、Windows License Activation、 169.254.169.254への通信、 DHCPトラフィック

有効化

ロググループ作成
フィルターする。Accept、Reject、ALL
送付先。S3、CWlogs
など

log format

  • VPC Flow logs Version
  • AWS Account ID
  • Network interface ID
  • src IP
  • dest IP
  • src port
  • dest port
  • protocol
  • packts
  • bytes
  • start
  • end
  • action(Accept or Reject)
  • log status
0
1
0

Register as a new user and use Qiita more conveniently

  1. You get articles that match your needs
  2. You can efficiently read back useful information
  3. You can use dark theme
What you can do with signing up
0
1

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?