Filter VPC flow logs to check connection between RDS mySQL and EC2

0

Connection between database and EC2 instance breaks at random times, even if there is 0 traffic and I have enabled VPC flow logs to figure out why. I can't seem to filter logs related to my RDS instance. I have tried filtering out logs according to my EC2 instance id, [let's say Instance ID is a123 and the filtered-out logs contain another instance ID, let's say b456 this is my custom flow log format: ${instance-id} ${srcaddr} ${srcport} ${pkt-srcaddr} ${pkt-src-aws-service} ${dstaddr} ${dstport} ${pkt-dstaddr} ${pkt-dst-aws-service} ${flow-direction} ${traffic-path} ${action} ${log-status}] and also port that my RDS instance uses, but it is not working.

2개 답변
0
수락된 답변

Simply put double quotes around the instance id.

AWS
LondonX
답변함 8달 전
profile pictureAWS
전문가
검토됨 8달 전
profile pictureAWS
전문가
검토됨 8달 전
0

You can use the following filter pattern in CloudWatch Logs to search (all logs streams) for either of the two IP addresses in the log group, for example:

  • 10.1.1.1 - server 1
  • 10.2.2.2 - server 2

like this:

%10\.1\.1\.1|10\.2\.2\.2%

Simply update this with your server IPs.

See more syntax rules here: https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/FilterAndPatternSyntax.html#matching-terms-events

AWS
LondonX
답변함 8달 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠