Skip to content

aws.ec2.describe_flow_logs

Example SQL Queries

SELECT * FROM
aws.ec2.describe_flow_logs;

Description

Describes one or more flow logs.

To view the published flow log records, you must view the log destination. For example, the CloudWatch Logs log group, the Amazon S3 bucket, or the Kinesis Data Firehose delivery stream.

Table Definition

Column NameColumn Data Type
dry_run Input Column

Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is DryRunOperation. Otherwise, it is UnauthorizedOperation.

BOOLEAN
filter Input Column

One or more filters.

  • deliver-log-status - The status of the logs delivery (SUCCESS | FAILED).

  • log-destination-type - The type of destination for the flow log data (cloud-watch-logs | s3 | kinesis-data-firehose).

  • flow-log-id - The ID of the flow log.

  • log-group-name - The name of the log group.

  • resource-id - The ID of the VPC, subnet, or network interface.

  • traffic-type - The type of traffic (ACCEPT | REJECT | ALL).

  • tag:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key Owner and the value TeamA, specify tag:Owner for the filter name and TeamA for the filter value.

  • tag-key - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.

STRUCT(
"name" VARCHAR,
"values" VARCHAR[]
)[]
Show child fields
filter[]
Show child fields
filter[].name

The name of the filter. Filter names are case-sensitive.

filter[].values[]
flow_log_ids Input Column

One or more flow log IDs.

Constraint: Maximum of 1000 flow log IDs.

VARCHAR[]
Show child fields
flow_log_ids[]
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

_aws_region Input Column

The AWS region to use.

VARCHAR
creation_time

The date and time the flow log was created.

TIMESTAMP_S
deliver_cross_account_role

The ARN of the IAM role that allows the service to publish flow logs across accounts.

VARCHAR
deliver_logs_error_message

Information about the error that occurred. Rate limited indicates that CloudWatch Logs throttling has been applied for one or more network interfaces, or that you've reached the limit on the number of log groups that you can create. Access error indicates that the IAM role associated with the flow log does not have sufficient permissions to publish to CloudWatch Logs. Unknown error indicates an internal error.

VARCHAR
deliver_logs_permission_arn

The ARN of the IAM role allows the service to publish logs to CloudWatch Logs.

VARCHAR
deliver_logs_status

The status of the logs delivery (SUCCESS | FAILED).

VARCHAR
destination_options

The destination options.

STRUCT(
"file_format" VARCHAR,
"hive_compatible_partitions" BOOLEAN,
"per_hour_partition" BOOLEAN
)
Show child fields
destination_options.file_format

The format for the flow log.

destination_options.hive_compatible_partitions

Indicates whether to use Hive-compatible prefixes for flow logs stored in Amazon S3.

destination_options.per_hour_partition

Indicates whether to partition the flow log per hour.

flow_log_id

The ID of the flow log.

VARCHAR
flow_log_status

The status of the flow log (ACTIVE).

VARCHAR
log_destination

The Amazon Resource Name (ARN) of the destination for the flow log data.

VARCHAR
log_destination_type

The type of destination for the flow log data.

VARCHAR
log_format

The format of the flow log record.

VARCHAR
log_group_name

The name of the flow log group.

VARCHAR
max_aggregation_interval

The maximum interval of time, in seconds, during which a flow of packets is captured and aggregated into a flow log record.

When a network interface is attached to a Nitro-based instance, the aggregation interval is always 60 seconds (1 minute) or less, regardless of the specified value.

Valid Values: 60 | 600

BIGINT
resource_id

The ID of the resource being monitored.

VARCHAR
tags

The tags for the flow log.

STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
Show child fields
tags[]
Show child fields
tags[].key

The key of the tag.

Constraints: Tag keys are case-sensitive and accept a maximum of 127 Unicode characters. May not begin with aws:.

tags[].value

The value of the tag.

Constraints: Tag values are case-sensitive and accept a maximum of 256 Unicode characters.

traffic_type

The type of traffic captured for the flow log.

VARCHAR