Steps to Enable and Analysis VPC Flow Logs in AWS

In this blog, we will show you the steps to enable and analysis VPC Flow Logs in AWS.

FLOW LOGS OVERVIEW

  • Flow logs are used to check the list of traffic( s ) that are accepted or rejected by the security group.
  • We can enable the flow logs at Interface Level, Subnet Level & VPC Level.
  • The VPC flow logs contain version, account-id, interface-id, src addr, dest addr, src port, dest port, protocol, packets bytes, start, end, action, and log status.
  • If we enable the flow logs at the VPC level, it will enable all the network interface connecting with it.

ENVIRONMENT OVERVIEW

 

  • We have created a VPC with 2 subnets in a different availability zone.

Steps to Enable and Analysis VPC Flow Logs in AWS

 

Steps to Enable and Analysis VPC Flow Logs in AWS

 

  • Also, We have created a windows EC2 instance for this demo.

Steps to Enable and Analysis VPC Flow Logs in AWS

 

ENABLING FLOW LOGS

 

  • Open the VPC dashboard and click on Your VPC’s.

Steps to Enable and Analysis VPC Flow Logs in AWS

 

  • Select the VPC and click on the Flow Logs tab.

Steps to Enable and Analysis VPC Flow Logs in AWS

 

  • Click on Create Flow log.

Steps to Enable and Analysis VPC Flow Logs in AWS

 

  • Select the Filter Type as All and select the destination as CloudWatch.

Steps to Enable and Analysis VPC Flow Logs in AWS

 

  • Provide the destination group name and click on the setup permission link.

Steps to Enable and Analysis VPC Flow Logs in AWS

 

  • For the demo purpose, leave the default settings and click on the Allow button.

Steps to Enable and Analysis VPC Flow Logs in AWS

 

  • Select the IAM Role named flowlogsRole from the drop-down list. Then click on the create button.

Steps to Enable and Analysis VPC Flow Logs in AWS

 

  • Flow log created successfully.

Steps to Enable and Analysis VPC Flow Logs in AWS

 

Steps to Enable and Analysis VPC Flow Logs in AWS

 

VERIFICATION

  • For the testing purpose, we try to telnet a few ports to gather logging.

Steps to Enable and Analysis VPC Flow Logs in AWS

 

  • Go to the cloud watch and click on logs option.

 

  • You will able to see the VPC log group in the cloud watch.

 

  • Now you can able to see the VPC flow logs as shown below.

 

  • We tested 3306 and 3389 ports and you can see the flow logs result below.

 

REFERENCE

Flow logs

 

Thanks for reading this blog. We hope it was useful for you to learn about the Steps to Enable and Analysis VPC Flow Logs in AWS.

Share on facebook
Facebook
Share on twitter
Twitter
Share on pinterest
Pinterest
Share on linkedin
LinkedIn
More Interested Related Posts
zfs pool usage

ZFS Pool and Dataset Usage

ZFS Pool and Dataset Usage   I am back with another blog to provide the useful script to the Freebsd users to determine the zpool

Assistanz Networks

Installing Zabbix Agent in FreeBSD 12.0

Zabbix Agent Installation and Configuration Guide on FreeBSD 12.0   Zabbix is an open-source monitoring software tool for diverse IT components, including networks, servers, virtual

DirectAdmin Server Management Plans

Premium Support

24/7 End User Support from your Helpdesk
$ 99 Monthly / Server
  • Unlimited Support Plan
  • 24/7 Emergency Phone
  • Chat Support for Admin
  • Separate Account Manager
  • NDA & SLA
  • SLA Review Meetings
  • FREE Consultancy Services
  • Simple SignUp Process
  • Instant Account Activation
  •  

Platinum Support

24/7 Proactive Support
$ 49 Monthly / Server
  • Unlimited Support Plan
  • 24/7 Emergency Phone
  • Chat Support for Admin
  • Separate Account Manager
  • Advance Proactive Monitoring
  • Guaranteed SLA
  • SLA Review Meetings
  • 3rd Party Application Support
  • FREE Consultancy Services
  • Server Migration Support
  • Weekly Status Report
  • No End User Support
Popular

Unlimited Support

24/7 Support

$ 30 Monthly / Server
  • Unlimited Support Plan
  • 24/7 Support
  • Basic Monitoring
  • 30 Minutes Response Time
  • 4 Hours Resolution time for the Possible Issues
  • Security and Performance Optimization
  • React to Customers queries
  • Simple SignUp Process
  • Instant Account Activation
  • No Third party application support
  • No Migration and End User Support

Cpanel Server Management Plans

Premium Support

24/7 End User Support from your Helpdesk

$ 99 Monthly / Server
  • 24/7 End User White Label Support
  • Unlimited Number of Tickets
  • Chat Support for Admin
  • Separate Account Manager
  • Guaranteed SLA
  • Weekly Status Reports
  • FREE Consultancy Services
  • Simple SignUp Process
  • Instant Account Activation

Platinum Support

24/7 Proactive Server Management
$ 49 Monthly / Server
  • Unlimited Support Plan
  • 24/7 Emergency Phone
  • Chat Support for Admin
  • Separate Account Manager
  • Advance Proactive Monitoring
  • Guaranteed SLA
  • SLA Review Meetings
  • 3rd Party Application Support
  • FREE Consultancy Services
  • Server Migration Support
  • Weekly Status Report
  • No End User Support
Popular

Unlimited Support

24/7 Server Management

$ 29 Monthly / Server
  • Unlimited Admin Tasks
  • 24/7 Support
  • Basic Monitoring
  • 30 Minutes Response time
  • 4 hours Response time for possible issues
  • Security and Performance Optimization
  • React to Customers queries
  • No Third party application support
  • No Migration and End User Support

Cpanel Server Management Plans

Premium Support

24/7 End User Support from your Helpdesk

$ 99 Monthly / Server
  • 24/7 End User White Label Support
  • Unlimited Number of Tickets
  • Chat Support for Admin
  • Separate Account Manager
  • Guaranteed SLA
  • Weekly Status Reports
  • FREE Consultancy Services
  • Simple SignUp Process
  • Instant Account Activation

Platinum Support

24/7 Proactive Server Management
$ 49 Monthly / Server
  • Unlimited Support Plan
  • 24/7 Emergency Phone
  • Chat Support for Admin
  • Separate Account Manager
  • Advance Proactive Monitoring
  • Guaranteed SLA
  • SLA Review Meetings
  • 3rd Party Application Support
  • FREE Consultancy Services
  • Server Migration Support
  • Weekly Status Report
  • No End User Support
Popular

Unlimited Support

24/7 Server Management

$ 29 Monthly / Server
  • Unlimited Admin Tasks
  • 24/7 Support
  • Basic Monitoring
  • 30 Minutes Response time
  • 4 hours Response time for possible issues
  • Security and Performance Optimization
  • React to Customers queries
  • No Third party application support
  • No Migration and End User Support