Log format

Once logging is enabled, you can view the logs in the CloudWatch logs console. Here is a summary of the type of information you will see in the flow-log (in order):

  • The VPC flow-logs version
  • The AWS account ID
  • The ID of the network interface
  • The source IPv4 or IPv6 address
  • The destination IPv4 or IPv6 address
  • The source port of the traffic
  • The destination port of the traffic
  • The IANA protocol number of the traffic
  • The number of packets transferred
  • The number of bytes transferred
  • The start time of the capture window (in Unix seconds)
  • The end time of the capture window (in Unix seconds)
  • The action associated with the traffic; for example, ACCEPT or REJECT
  • The logging status of the flow-log; for example, OK, NODATA, or SKIPDATA

Get AWS Administration Cookbook now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.