Description
VPC Flow Logs support incident response, access-path analysis and policy validation. Missing records make suspicious communication harder to trace later.
Flow logs are sampled and aggregated records, not full packet captures. Higher-level or Network Management API configurations can apply in addition to a subnet’s log_config, so check actual collection.
Potential impact
- Evidence for investigating suspicious traffic and its impact can be insufficient.
- Verifying traffic effects after firewall changes can become harder.
Remediation
- For subnet-level configuration, set
log_configaggregation, sampling and metadata to meet operational requirements. - Check higher-level settings and verify log arrival, retention and access permissions in Cloud Logging.
Examples
Define the referenced VPC and project separately. The after example’s ten-minute aggregation and 0.5 sampling are illustrative; adjust them to investigation requirements and cost.
Before
hcl
resource "google_compute_subnetwork" "subnet" {
name = "log-test-subnetwork"
ip_cidr_range = "10.2.0.0/16"
region = "us-central1"
network = google_compute_network.custom.id
}
After
hcl
resource "google_compute_subnetwork" "subnet" {
name = "log-test-subnetwork"
ip_cidr_range = "10.2.0.0/16"
region = "us-central1"
network = google_compute_network.custom.id
log_config {
aggregation_interval = "INTERVAL_10_MIN"
flow_sampling = 0.5
metadata = "INCLUDE_ALL_METADATA"
}
}
Explanation:
- Before: No subnet-level flow-log setting is present. Check collection configured at other scopes separately.
- After: Subnet-level collection is configured. It records sampled flows rather than retaining every packet.