Description
VPC Flow Logs collect information about IP traffic to and from network interfaces. They can be configured for an entire VPC, a subnet, or a network interface.
Potential impact
Without logs for the required scope, evidence for investigating abnormal communication or access paths is reduced.
Remediation
Specify the appropriate one of vpc_id, subnet_id, or eni_id in aws_flow_log. Configure the log destination and delivery permissions, and verify that the required traffic is recorded.
Examples
The first Flow Log in the before example is invalid because it has no target. The second already targets the main VPC. After the change, both Flow Logs specify that VPC; log groups and the IAM role are defined separately.
Before
hcl
resource "aws_vpc" "main" {
cidr_block = "10.0.0.0/16"
}
resource "aws_flow_log" "example" {
iam_role_arn = aws_iam_role.example.arn
log_destination = aws_cloudwatch_log_group.example.arn
traffic_type = "ALL"
}
resource "aws_flow_log" "example1" {
iam_role_arn = aws_iam_role.example.arn
log_destination = aws_cloudwatch_log_group.main.arn
traffic_type = "ALL"
vpc_id = aws_vpc.main.id
}
After
hcl
resource "aws_vpc" "main" {
cidr_block = "10.0.0.0/16"
}
resource "aws_flow_log" "example" {
iam_role_arn = aws_iam_role.example.arn
log_destination = aws_cloudwatch_log_group.example.arn
traffic_type = "ALL"
vpc_id = aws_vpc.main.id
}
resource "aws_flow_log" "example2" {
iam_role_arn = aws_iam_role.example.arn
log_destination = aws_cloudwatch_log_group.example.arn
traffic_type = "ALL"
vpc_id = aws_vpc.main.id
}