All technological notes.
VPC Flow Logs
Capture information about IP traffic going into your interfaces:
S3, CloudWatch Logs, and Kinesis Data FirehoseCaptures network information from AWS managed interfaces too:

srcaddr & dstaddr – help identify problematic IPsrcport & dstport – help identity problematic portsAction – success or failure of the request due to Security Group / NACLAthena on S3 or CloudWatch Logs InsightsLook at the ACTION field
Incoming Requests
REJECT => NACL or SGACCEPT, Outbound REJECT => NACL (stateless, sg=stateful)
REJECT => NACL or SGACCEPT, Inbound REJECT => NACL(stateless, sg=stateful)








Analyze using Athena with S3
Create a bucket for athena



Create Athena table for flow log
Location of URI in the S3 where flow log is stored.


Alter table for dates
URI to replace











