AWS VPC Content Pack

The following content pack is available for use with a Graylog Illuminate license and Graylog Enterprise or Graylog Security. Contact sales to learn more about obtaining Illuminate.

AWS VPC Flow Logs capture network traffic metadata for AWS resources. This content pack parses and normalizes AWS VPC Flow Logs for analysis and monitoring.

Supported/Tested Versions

  • AWS VPC Flow logs (Version 2 default schema)

Hint: This pack is tested with AWS VPC Flow Logs using the default schema.

Warning: Custom log formats are not supported.

Requirements

  • Graylog 6.2.0+

Stream Configuration

This technology pack includes 1 stream:

  • "Illuminate:AWS Kinesis Messages"

Hint: If this stream does not exist prior to the activation of this pack then it is created and configured to route messages to this stream and the associated index set. There should not be any stream rules configured for this stream.

Index Set Configuration

This technology pack includes 1 index set definition:

  • "AWS Kinesis Logs"

Hint: If this index set is already defined, then nothing is changed. If this index set does not exist, then it is created with retention settings of a daily rotation and 90 days of retention. These settings can be adjusted as required after installation.

Log Collection

This pack parses logs from the following sources:

  • AWS Kinesis/CloudWatch input

AWS Kinesis/CloudWatch Input Configuration

Please refer to the official documentation to set up AWS Kinesis/CloudWatch input.

Log Format Example

These are example logs for AWS VPC Flow Logs for the message field.

VPC Flow Logs

# Kinesis VPC Flow logs eni-094fad06ebf11ad6b ACCEPT TCP 10.0.2.155:50602 -> 35.92.124.220:443 eni-094fad06ebf11ad6b REJECT TCP 79.124.40.134:49683 -> 10.0.2.155:2838 eni-0e2564b556d45f08d - IP -:0 -> -:0

What Is Provided

  • Rules to parse, normalize, and enrich AWS VPC messages.

Events Processed by This Technology Pack

The content pack supports the following log types. Generic processing is provided for log types not listed.

  • AWS VPC Flow Logs

GIM Categorization

GIM categorization is provided for the following messages:

Event Type gim_event_type_code GIM Category GIM Subcategory GIM Event Type
VPC Flow Log 120500 network network.flow flow record

Message Fields Included in This Pack

General Parsing for AWS VPC Flow Logs

AWS VPC Content Pack

This spotlight offers a dashboard with 1 tab:

Overview