logo

Gain visibility into DDoS attacks with flow logs in AWS Shield Advanced

ID: 115a70fc-eff2-5152-a8e6-f2bc887e9de3

STIX ID: report--115a70fc-eff2-5152-a8e6-f2bc887e9de3

Feed Name: AWS Security Blog

Date Published: 2026-06-04

Date Updated: 2026-06-05

Author: Ken Kitts

...
...

This AWS Shield Advanced guide explains attack flow logs that capture metadata during DDoS events, lists the log fields (source/destination IPs and ports, protocol, packets/bytes, action, location, tcp_flags, srccountry, etc.), describes benefits and supported output formats, and provides step-by-step instructions to configure delivery to Amazon S3, CloudWatch Logs, or Data Firehose including prerequisites, permissions, and cleanup.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.