Description
VPC Flow Logs record IP traffic information for network interfaces, helping investigate connection problems and suspicious communication. Missing flow records for the required scope can leave gaps in incident evidence.
Check existing coverage at the VPC, subnet and network-interface levels together. Flow logs do not record packet contents or every kind of traffic, and an IP address alone does not establish a user’s identity.
Potential impact
- Investigating addresses, ports and accepted or rejected traffic may be harder.
- Finding the cause of connection failures or access problems may take longer.
Remediation
Set ResourceId and ResourceType on AWS::EC2::FlowLog to the actual collection target. Choose TrafficType to include the required accepted and rejected traffic, and prepare the destination and delivery permissions. Verify collection, access restrictions and retention.
Examples
These excerpts send logs to CloudWatch Logs. Prepare Role and LogGroup separately. In the before example, MyVPC1 must be defined as an input or resource representing another actual VPC.
Before
Resources:
MyVPC:
Type: AWS::EC2::VPC
Properties:
CidrBlock: 10.0.0.0/16
FlowLog:
Type: AWS::EC2::FlowLog
Properties:
DeliverLogsPermissionArn: !GetAtt Role.Arn
LogGroupName: !Ref LogGroup
ResourceId: !Ref MyVPC1
ResourceType: VPC
TrafficType: ACCEPT
The flow log targets MyVPC1 rather than MyVPC. This configuration does not collect traffic for MyVPC.
After
Resources:
MyVPC:
Type: AWS::EC2::VPC
Properties:
CidrBlock: 10.0.0.0/16
FlowLog:
Type: AWS::EC2::FlowLog
Properties:
DeliverLogsPermissionArn: !GetAtt Role.Arn
LogGroupName: !Ref LogGroup
ResourceId: !Ref MyVPC
ResourceType: VPC
TrafficType: ACCEPT
The target is corrected to MyVPC. TrafficType: ACCEPT includes accepted traffic only; select appropriate coverage such as ALL if rejected traffic is also required.