Review VPC Flow Logs coverage

Use VPC Flow Logs to record the network scope needed for investigations.

Description

VPC Flow Logs collect information about IP traffic to and from network interfaces. They can be configured for an entire VPC, a subnet, or a network interface.

Potential impact

Without logs for the required scope, evidence for investigating abnormal communication or access paths is reduced.

Remediation

Specify the appropriate one of vpc_id, subnet_id, or eni_id in aws_flow_log. Configure the log destination and delivery permissions, and verify that the required traffic is recorded.

Examples

The first Flow Log in the before example is invalid because it has no target. The second already targets the main VPC. After the change, both Flow Logs specify that VPC; log groups and the IAM role are defined separately.

Before

hcl
resource "aws_vpc" "main" {
  cidr_block = "10.0.0.0/16"
}

resource "aws_flow_log" "example" {
  iam_role_arn    = aws_iam_role.example.arn
  log_destination = aws_cloudwatch_log_group.example.arn
  traffic_type    = "ALL"
}

resource "aws_flow_log" "example1" {
  iam_role_arn    = aws_iam_role.example.arn
  log_destination = aws_cloudwatch_log_group.main.arn
  traffic_type    = "ALL"
  vpc_id          = aws_vpc.main.id
}

After

hcl
resource "aws_vpc" "main" {
  cidr_block = "10.0.0.0/16"
}

resource "aws_flow_log" "example" {
  iam_role_arn    = aws_iam_role.example.arn
  log_destination = aws_cloudwatch_log_group.example.arn
  traffic_type    = "ALL"
  vpc_id          = aws_vpc.main.id
}

resource "aws_flow_log" "example2" {
  iam_role_arn    = aws_iam_role.example.arn
  log_destination = aws_cloudwatch_log_group.example.arn
  traffic_type    = "ALL"
  vpc_id          = aws_vpc.main.id
}

References