activity_dashboard_accepted_rejected_trafficactivity_dashboard_top_destination_ips_by_trafficactivity_dashboard_top_enis_by_trafficactivity_dashboard_top_source_destination_pairs_by_packetsactivity_dashboard_top_source_ips_by_rejected_trafficactivity_dashboard_top_source_ips_by_trafficactivity_dashboard_total_accepted_trafficactivity_dashboard_total_recordsactivity_dashboard_total_rejected_trafficactivity_dashboard_traffic_by_log_statusactivity_dashboard_traffic_by_protocolactivity_dashboard_traffic_by_regiondatabase_traffichigh_packet_trafficlarge_data_transferrdp_trafficssh_traffictraffic_with_unusual_protocols
Query: Traffic by Protocol
Description
Distribution of record counts across different protocols.
Usage
powerpipe query aws_vpc_flow_log_detections.query.activity_dashboard_traffic_by_protocol
Tailpipe Tables
Tags
SQL
select case when protocol = 1 then 'ICMP' when protocol = 6 then 'TCP' when protocol = 17 then 'UDP' else 'Other' end as protocol_type, count(*) as "Records"from aws_vpc_flow_logwhere protocol is not nullgroup by protocol_typeorder by "Records" desc;
Dashboards
The query is used in the dashboards: