Review GCP subnet VPC Flow Logs collection

Verify that the required network flow records are actually collected.

Description

VPC Flow Logs support incident response, access-path analysis and policy validation. Missing records make suspicious communication harder to trace later.

Flow logs are sampled and aggregated records, not full packet captures. Higher-level or Network Management API configurations can apply in addition to a subnet’s log_config, so check actual collection.

Potential impact

  • Evidence for investigating suspicious traffic and its impact can be insufficient.
  • Verifying traffic effects after firewall changes can become harder.

Remediation

  • For subnet-level configuration, set log_config aggregation, sampling and metadata to meet operational requirements.
  • Check higher-level settings and verify log arrival, retention and access permissions in Cloud Logging.

Examples

Define the referenced VPC and project separately. The after example’s ten-minute aggregation and 0.5 sampling are illustrative; adjust them to investigation requirements and cost.

Before

hcl
resource "google_compute_subnetwork" "subnet" {
  name          = "log-test-subnetwork"
  ip_cidr_range = "10.2.0.0/16"
  region        = "us-central1"
  network       = google_compute_network.custom.id
}

After

hcl
resource "google_compute_subnetwork" "subnet" {
  name          = "log-test-subnetwork"
  ip_cidr_range = "10.2.0.0/16"
  region        = "us-central1"
  network       = google_compute_network.custom.id

  log_config {
    aggregation_interval = "INTERVAL_10_MIN"
    flow_sampling        = 0.5
    metadata             = "INCLUDE_ALL_METADATA"
  }
}

Explanation:

  • Before: No subnet-level flow-log setting is present. Check collection configured at other scopes separately.
  • After: Subnet-level collection is configured. It records sampled flows rather than retaining every packet.

References