All Products
Search
Document Center

Cloud Config:vpc-flow-logs-enabled

Last Updated:Nov 10, 2025

Checks whether the flow log feature is enabled for each virtual private cloud (VPC).

Scenario

VPC provides flow logs that record information about inbound and outbound traffic of an elastic network interface (ENI). Flow logs help verify access control list (ACL) rules, monitor network traffic, and troubleshoot network issues.

Risk level

Default risk level: low.

You can change the risk level as required when you apply this rule.

Compliance evaluation logic

  • If the flow log feature is enabled for each VPC, the evaluation result is compliant.
  • If the flow log feature is disabled for a VPC, the evaluation result is non-compliant. For more information about how to correct the non-compliant configuration, see Non-compliance remediation.

Rule details

ItemDescription
Rule namevpc-flow-logs-enabled
Rule IDvpc-flow-logs-enabled
TagVPC, Flowlog, and AuditBaseline
Automatic remediationNot supported
Trigger typePeriodic execution
Time interval24 hours
Supported resource typeVPC
Input parameterNone

Non-compliance remediation

Enable the flow log feature for the VPC. For more information, see Create and manage a flow log.