Query VPC flow logs in Cloudwatch insights

0

I'm trying to figure out how much traffic is going to a 10.25.x.x via our VPC flow logs. How can I do that in Cloudwatch Insights? I can't work out how to get 10.25.* to query

AWS
专家
已提问 4 年前2212 查看次数
1 回答
1
已接受的回答

There are two ways to do it, you can use the like clause on the filter like in the following example:

fields @timestamp, srcAddr
| sort @timestamp desc
| limit 20
| filter srcAddr like "10.25."

Second option is to use one of the ip functions to check to see if the ip address is in the subnet and in your case the subnet you need is 10.25.0.0/16

fields @timestamp, srcAddr
| sort @timestamp desc
| limit 20
| filter isIpv4InSubnet(srcAddr,"10.25.0.0/16")

Addtionally, here is a query that returns total bytes directed at the range of destination IPs in your range:

stats sum(bytes)
| sort @timestamp desc
| filter isIpv4InSubnet(dstAddr,"10.25.0.0/16")
AWS
专家
已回答 4 年前

您未登录。 登录 发布回答。

一个好的回答可以清楚地解答问题和提供建设性反馈,并能促进提问者的职业发展。

回答问题的准则