Description
VPC flow logs support investigation of network communication patterns and connection problems. Missing logs for the required scope can leave too little information to investigate unusual traffic or failed connections.
Potential impact
- Unusual communication and excessive traffic become harder to trace.
- Investigating network paths after a security incident or operational failure can take longer.
Remediation
Enable flow logs for the VPC, vSwitch or network-interface scope needed for investigation. Check resource_id, resource_type and traffic_type, then verify the destination, retention and actual log delivery.
Examples
These excerpts add flow logging at VPC scope. Prepare the Simple Log Service project and Logstore separately and supply them through the variables.
Before
resource "alicloud_vpc" "main" {
cidr_block = "192.168.0.0/24"
name = var.name
}
After
resource "alicloud_vpc" "main" {
cidr_block = "192.168.0.0/24"
name = var.name
}
resource "alicloud_vpc_flow_log" "default" {
resource_id = alicloud_vpc.main.id
resource_type = "VPC"
traffic_type = "All"
log_store_name = var.log_store_name
project_name = var.project_name
flow_log_name = var.name
status = "Active"
}
The after example attaches an Active flow log to the VPC and collects allowed and denied traffic. Flow logs record traffic metadata; they do not capture complete packet contents.