Control: 3.3 Ensure VPC flow logging is enabled in all VPCs
You can use the flow log function to monitor the IP traffic information for an ENI, a VSwitch or a VPC. If you create a flow log for a VSwitch or a VPC, all the Elastic Network Interfaces, including the newly created Elastic Network Interfaces, are monitored. Such flow log data is stored in Log Service, where you can view and analyze IP traffic information. It is recommended that VPC Flow Logs be enabled for packet "Rejects" for VPCs.
- Logon to VPC console.
- In the left-side navigation pane, click
- Follow the instruction to create
FlowLogfor each of your VPCs.
Run the control in your terminal:
steampipe check alicloud_compliance.control.cis_v100_3_3
Snapshot and share results via Steampipe Cloud:
steampipe loginsteampipe check --share alicloud_compliance.control.cis_v100_3_3
This control uses a named query:manual_control