Network Flow Logs across clouds
The record of every connection through a network - VPC Flow Logs, NSG and VNet flow logs, VCN flow logs - in the format an investigation needs, kept where it can be queried.
7 verified modules - all static-validated and publish-checked; live-test pending.
Compare by provider
| Provider | Module | Verification |
|---|---|---|
| Alibaba Cloud | VPC Flow Logs to a Log Service Logstore, All Traffic, at One Minute, with Retention | static-validated |
| AWS | Flow Logs for an Existing VPC in the Extended Format, at One Minute, All Traffic | static-validated |
| Azure | Flow Logs that Are On, Kept, and Analysed | static-validated |
| Huawei Cloud | VPC Flow Logs to a Log Tank Service Stream, All Traffic, VPC-Wide Rather Than per Port | static-validated |
| IBM Cloud | A Flow Log Collector with the Authorization Without Which Its Writes Never Land | static-validated |
| Oracle Cloud | VCN Flow Logs per Subnet, All Traffic, with Retention Past the Default Month | static-validated |
| Tencent Cloud | VPC Flow Logs to a Cloud Log Service Topic, All Traffic, with the Retention You Choose | static-validated |
How to choose
Compare what is logged by default (accepted and rejected, or one), how fine the time is (one minute or ten), which fields the record carries (flow direction, TCP flags and packet-level addresses are the ones that matter and the ones the defaults leave out), and where the log lands and what that costs per gigabyte.
When not to use
Flow logs are metadata: who talked to whom, when and how much, never what was said. They are the largest log a network produces and the one nobody reads until the day after the incident; the retention is the decision.