Omissions

Some traffic is not captured by the flow-logs service, as follows:

  • Traffic to the Amazon DNS server (x.x.x.2 in your allocated range)
  • Traffic for Amazon Windows license activation (obviously only applicable to Windows instances)
  • Traffic to and from the instance metadata service (that is, IP address 169.254.169.254)
  • DHCP traffic
  • Traffic to the reserved VPC IP address for the default VPC router (x.x.x.1 in your allocated range)

Get AWS Administration Cookbook now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.