Control: 3.3 Ensure VPC flow logging is enabled in all VPCs
Description
You can use the flow log function to monitor the IP traffic information for an ENI, a VSwitch or a VPC. If you create a flow log for a VSwitch or a VPC, all the Elastic Network Interfaces, including the newly created Elastic Network Interfaces, are monitored. Such flow log data is stored in Log Service, where you can view and analyze IP traffic information. It is recommended that VPC Flow Logs be enabled for packet "Rejects" for VPCs.
Remediation
From Console
- Logon to VPC console.
- In the left-side navigation pane, click
FlowLog
. - Follow the instruction to create
FlowLog
for each of your VPCs.
Usage
Run the control in your terminal:
powerpipe control run alicloud_compliance.control.cis_v100_3_3
Snapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run alicloud_compliance.control.cis_v100_3_3 --share
SQL
This control uses a named query:
manual_control