Add support for custom Flow Logs format #10081
Labels
enhancement
Requests to existing resources that expand the functionality or scope.
service/ec2
Issues and PRs that pertain to the ec2 service.
Milestone
Community Note
Description
AWS has announced support for custom VPC Flow Logs format, which now allows to inclusion of additional metadata fields like
vpc-id
,subnet-id
,instance-id
,tcp-flags
,type
,pkt-srcaddr
,pkt-dstaddr
in Amazon Virtual Private Cloud (Amazon VPC) flow logs to better understand network flows.Usage of additional metadata fields like
vpc-id
,subnet-id
, Transmission Control Protocol (TCP) bitmask reduce the number of computations and look-ups required to extract meaningful information from the log data. For example, you can use TCP bitmask to identify the resource initiating at TCP connection. Similarly, you can use the packet source and destination IP fields to identify the source resource and the intended target of a connection passing through a network interface attached to NAT Gateway or an AWS Transit Gateway.New or Affected Resource(s)
Potential Terraform Configuration
Note: the use of
${}
in flow log configuration format conflicts with Terraform variable interpolation syntax, so there may be a need to use different symbols to denote log metadata attributes and escape them like I did in the above example.References
The text was updated successfully, but these errors were encountered: