Viewing AWS flow log data
Flow logs that are received through Amazon Web Service (AWS) integrations include extra
properties in the flow information.
About this task
In addition to the standard normalized flow properties, the following properties are shown for
AWS flow logs:
- Interface name (available for all IPFIX flows that send this field)
- Region (available for all IPFIX flows that send this field)
- Firewall Name (available for all IPFIX flows that send this field)
- Firewall Event (enumerated, available for all IPFIX flows that send this field)
- AWS Action (enumerated)
- AWS Log Status (enumerated)
- AWS Account ID
- VPC ID New in 7.5.0
- Subnet ID New in 7.5.0
- Instance ID New in 7.5.0
The following table shows the string description for each of the enumerated fields:
| Enumerated field | String description |
|---|---|
| Firewall Event |
The numerical values for the Firewall Event field map to the following descriptions:
|
| AWS Action |
The numerical values for the AWS Action field map to the following descriptions:
|
| AWS Log Status |
The numerical values for the AWS Log Status field map to the following descriptions:
|
Procedure
To include the description for the enumerated property in your query results, you must include
the LOOKUP function in your AQL search string.