VPC flow logs capture inbound and outbound traffic for elastic network interfaces (ENIs). Use flow logs to monitor network performance, troubleshoot network faults, and optimize traffic costs.
How it works
You can create flow logs to capture traffic at three levels of granularity: an elastic network interface (ENI), a vSwitch, or a VPC. If you create a flow log for a VPC or a vSwitch, the system captures traffic from all associated ENIs, including any ENIs created later.
During each capture window, which is 10 minutes by default, the system aggregates traffic data into flow log entries and delivers them to Simple Log Service.
Each flow log entry captures a specific 5-tuple network flow for a capture window. The entry includes fields for the source and destination IP addresses, source and destination ports, and the protocol. For example:
Eni-id | Direction | Srcaddr | Srcport | Protocol | Dstaddr | Dstport | ... |
eni-xxx | in | 10.0.0.1 | 53870 | 6 | 10.0.0.2 | 80 | ... |
eni-xxx | out | 10.0.0.2 | 80 | 6 | 10.0.0.1 | 53870 | ... |
For a description of all fields, see Flow log fields.
To reduce costs, you can capture traffic only from specific paths. Available paths include:
Traffic to the internet through an IPv4 gateway
Traffic through a NAT Gateway
Traffic through a VPN Gateway
Traffic through a Transit Router (TR)
Traffic to a cloud service through a gateway endpoint
Traffic to an Express Connect circuit through a virtual border router (VBR)
Traffic through an Express Connect Router (ECR)
Traffic through a Gateway Load Balancer endpoint
Traffic to the internet
Capturing traffic from an Internet-facing Classic Load Balancer (CLB) to the internet is not supported.
Common use cases for flow logs include:
Network monitoring: Monitor VPC throughput and performance, analyze traffic patterns and trends for resources within a VPC, troubleshoot network issues, and verify that security group and network ACL rules are working as expected.
Network cost optimization: Analyze network traffic to optimize your data transfer costs. For example, you can identify traffic from a VPC to other regions, to specific public IP addresses, or to on-premises data centers and other cloud networks. You can also locate ECS instances within your VPC that generate significant traffic.
Security analysis: During a security incident, you can analyze inbound and outbound traffic to identify suspicious IP addresses or investigate access from malicious IPs.
Limitations
To use flow logs for the first time, you must:
On the Flow log, click Activate Now. If you created flow log instances during the public preview, you must still click Activate Now to view and manage these instances.
On the Flow log, click Authorize Now, and then click Authorize. This action automatically creates a RAM role named
AliyunVPCLogArchiveRoleand a RAM policy namedAliyunVPCLogArchiveRolePolicy. VPC uses this role and policy by default to access Simple Log Service and write flow logs to it.Activate Simple Log Service on the Simple Log Service product page.
After you enable flow logs, the initial traffic capture for a new elastic network interface may be delayed, typically by less than 10 minutes.
Flow logs do not capture multicast traffic.
When customizing subscription fields, you must subscribe to at least one field. If you also deliver logs to NIS Traffic Analyzer, the subscription must meet the NIS minimum required field set validation rules.
Manage flow logs
Console
Create a flow log
Go to the Flow log in the VPC console and click Create a flow log. In the Create a flow log panel, configure the following parameters:
Collection Configuration:
Region: Select the region of the target resource.
Resource Type and Resource Instance: Select the collection granularity. You can select VPC, vSwitch, or ENI. If you select a VPC or vSwitch, the system monitors traffic for all ENIs within the selected resource.
Data Transfer Type: Select whether to capture traffic that is allowed or rejected by access controls, such as security group and network ACL rules.
IP Version: Select IPv4 to capture only IPv4 traffic, or select Dual-stack to capture both IPv4 and IPv6 traffic. The following regions support IPv6: China (Hangzhou), China (Shanghai), China (Qingdao), China (Beijing), China (Hohhot), China (Shenzhen), Singapore, US (Silicon Valley), and US (Virginia).
Sampling Interval (Minutes): Specifies the duration of the capture window for aggregating traffic information. You can set the interval to 1, 5, or 10 minutes. A shorter interval generates flow logs more frequently and provides more timely data, which helps you detect and locate issues faster. A longer interval provides less timely data but reduces the number of log entries and helps save costs.
For example, for a TCP session that maintains a persistent connection, a 1-minute window produces 60 log entries per hour, while a 10-minute window produces only 6 log entries.
If multiple flow log instances in a VPC collect traffic from the same ENI, the system uses the shortest sampling interval among all instances as the actual capture period.
Sampling Path: To reduce costs, you can select specific capture scenarios. To select a specific scenario, first deselect the default All Scenarios option.
You can capture traffic that passes through the following network components: an IPv4 gateway, a NAT Gateway, a VPN Gateway, a Transit Router (TR), a gateway endpoint, a virtual border router (VBR), an Express Connect Router (ECR), a Gateway Load Balancer (GWLB) Endpoint, and traffic to the Internet.
Analysis and Delivery: You can deliver logs to Log Service (SLS) and NIS Traffic Analyzer. You can deliver logs to Log Service only when you create the flow log. If you disable this feature, you cannot re-enable it.
Deliver to Log Service:
Select a project and Logstore: When you create your first flow log, we recommend that you click Create Project and Create Logstore to isolate the data. To consolidate multiple flow logs for centralized analysis, select the same Logstore.
Enable Log Analysis Report: We recommend that you select this option. This feature automatically creates an index and a dashboard for the Logstore that contains your flow logs, allowing you to perform SQL queries and visual analysis on the logs. After you enable this feature, charges are incurred for using Log Service (SLS).
Enable NIS Traffic Analysis: Select NIS Traffic Analyzer to perform traffic analysis. If the selection list is empty, you must first Create NIS Traffic Analyzer. Ensure that the NIS Traffic Analyzer that you create or select has a The sampling interval of the traffic analyzer must be greater than that of the flow log.
Supported regions for integrating VPC flow logs with an NIS Traffic Analyzer.
After you create the flow log, the system automatically starts to capture traffic. You can then analyze flow logs.
Start or stop a flow log
On the Flow log in the VPC console, find the target flow log and click Start or Stop in the Actions column.
After you stop a flow log, you are no longer charged for generating flow logs. However, Log Service (SLS) continues to bill you for storing the existing flow logs.
Delete a flow log
On the Flow log in the VPC console, find the target flow log and click Delete in the Actions column.
After you delete a flow log, you are no longer charged for generating flow logs. However, Log Service (SLS) continues to Billing. To stop all charges, go to the Log Service console and Manage Logstores.
API
Before creating a flow log, ensure you have enabled the flow log feature and created a project and Logstore in Log Service (SLS):
Call OpenFlowLogService to enable the flow log feature.
Call CreateProject to create a project, and call CreateLogStore to create a Logstore.
After meeting these prerequisites, you can perform the following operations:
Call CreateFlowLog to create a flow log, and optionally call CreateIndex to create an index.
Call ModifyFlowLogAttribute to modify flow log attributes. You can modify the flow log name, description, aggregation interval, and custom subscription.
Call DeactiveFlowLog to stop a flow log.
Call ActiveFlowLog to start a flow log.
Call DeleteFlowLog to delete a flow log.
Terraform
Resources: alicloud_log_project, alicloud_log_store, alicloud_vpc_flow_log
# Specify the region where you want to create the flow log.
provider "alicloud" {
region = "cn-hangzhou"
}
# Specify the description of the project and the names of the Logstore and flow log.
variable "name" {
default = "vpc-flowlog-example"
}
# Generate a random string to use in the project name.
resource "random_uuid" "example" {
}
# Create a Log Service project.
resource "alicloud_log_project" "example" {
project_name = substr("tf-example-${replace(random_uuid.example.result, "-", "")}", 0, 16)
description = var.name
}
# Create a Log Service Logstore.
resource "alicloud_log_store" "example" {
project_name = alicloud_log_project.example.project_name
logstore_name = var.name
shard_count = 3
auto_split = true
max_split_shard_count = 60
append_meta = true
}
# Create a VPC flow log.
resource "alicloud_vpc_flow_log" "example" {
flow_log_name = var.name
log_store_name = alicloud_log_store.example.logstore_name
description = var.name
traffic_path = ["all"] # Capture traffic from all scenarios.
project_name = alicloud_log_project.example.project_name
resource_type = "VPC" # Resource type.
resource_id = "vpc-bp1ekmgzch0bo3hxXXXXXX" # VPC ID.
aggregation_interval = "1" # Aggregation interval in minutes.
traffic_type = "All" # Capture all allowed and rejected traffic.
}Analyze flow logs
Analyzing flow logs helps you monitor network performance, troubleshoot network issues, optimize traffic costs, and analyze network security.
Console
Custom analysis in a Logstore
Go to the Flow log in the VPC console. In the Simple Log Service column of the target flow log, click the Logstore name to open the Logstore details page. On this page, you can:
View Raw Logs to see detailed flow log entries.
Enter a statement to query and analyze flow logs.
The Logstore query interface provides three tabs: Raw Logs, Graph, and Log Clustering. You can set the query time range. The upper area displays a timeline chart of log volume distribution, and the lower area displays a table of query results with fields such as srcaddr, dstaddr, and protocol.
Analysis with preset templates
The Flow Log Center provides visualization templates to quickly analyze VPC flow logs. The templates support VPC policy statistics, elastic network interface traffic statistics, and traffic statistics between CIDR blocks.
Go to the Flowlog center page and click Add in the upper-right corner.
In the Create Instance panel, enter an Instance Name, select the Project and Logstore that contain the existing flow log, and click OK.
After the instance is created, click its instance ID in the Flow Log Center. On the Flow Log Details page, you can view and analyze the flow logs.
The Monitoring Center provides the following dashboards and custom query features:
Overview: Displays accept and reject trends for flow logs, inbound and outbound traffic trends, the total number of packets and bytes for each VPC and elastic network interface (ENI), and the geographic distribution of source and destination IP addresses.
Policy Statistics: Displays Accept and Reject trends, and statistics for the number of accepted and rejected events based on the 5-tuple. A 5-tuple consists of a source IP address, source port, protocol type, destination IP address, and destination port.
Accept: Traffic that is allowed by security groups and network ACLs.
Reject: Traffic that is rejected by security groups and network ACLs.
ENI Traffic: Displays inbound and outbound traffic information for elastic network interfaces.
Inter-ECS Traffic: Displays traffic between ECS instances.
Custom Query: You can write your own queries. For instructions, see Quick guide to queries and analysis.
Enable inter-domain analysis (optional): On the Flow Log Details page, click CIDR Block Settings. On the CIDR Block Settings tab, turn on the Inter-Domain Analysis switch.
After you enable the inter-domain analysis feature, the system automatically creates a data transformation task. This task generates VPC flow logs that include CIDR block information for analyzing traffic between different CIDR blocks. The data transformation feature incurs charges.
Simple Log Service provides multiple predefined CIDR blocks. To analyze traffic between different CIDR blocks, you can enable the inter-domain analysis feature with a single click. You can also add custom CIDR blocks as needed.
Three types of CIDR blocks are predefined by default: Private network (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16 - adjustable based on your actual configuration), Alibaba Cloud services (partial) (100:64.0.0/10), and Internet (all CIDR blocks other than those listed above). Each CIDR block type supports edit and delete operations.
The Inter-domain Analysis feature provides the following dashboards and custom query features:
Inter-domain Traffic: Displays traffic between different CIDR blocks.
ECS-to-Domain Traffic: Displays traffic from ECS instances to destination CIDR blocks.
Threat Intelligence: Displays threat intelligence for source and destination IP addresses.
Custom Query: You can write queries to query and analyze VPC flow logs that contain CIDR block information.
API
Call GetLogsV2 to query and analyze flow logs.
Examples
This topic provides four examples of common use cases.
Source IPs for public access
In this scenario, you have a web server that is accessible from the Internet and listens on port 80. You have also configured security group rules to control access from specific source IPs.
By creating a flow log, you can identify the source IPs that access port 80 and determine how many of their requests your security group rules allow or reject.
Create a flow log
For Resource Instance, select the ENI of the web server.
For Data Transfer Type, select All Traffic.
For delivery settings, select Deliver to Log Service and enable the Enable Log Analysis Report.
Keep the default values for other settings.
Analyze the flow logs
Query and analysis statement
Filter for traffic to port 80 on the server at 10.0.0.1, and display the number of times each source IP was allowed or rejected by the security group:
dstaddr:10.0.0.1 AND dstport:80 | SELECT -- Filter for logs where the destination IP is 10.0.0.1 and the destination port is 80 srcaddr, SUM(CASE WHEN action = 'ACCEPT' THEN 1 ELSE 0 END) AS accept_count, -- Count 1 for each 'ACCEPT' (allowed) action SUM(CASE WHEN action = 'REJECT' THEN 1 ELSE 0 END) AS reject_count -- Count 1 for each 'REJECT' (rejected) action FROM log GROUP BY srcaddr -- Group the results by source IP address ORDER BY accept_count + reject_count DESC -- Sort results in descending order by the total number of allowed and rejected connectionsResult preview
The
srcaddrcolumn lists the source IPs that accessed port 80. Theaccept_countandreject_countcolumns show how many times the security group allowed or rejected connections from each source IP during the specified time range:Five source IPs accessed port 80: 120.26.XX.XX, 121.43.XX.XX, 154.212.XX.XX, 176.65.XX.XX, and 198.235.XX.XX.
All requests from 120.26.XX.XX were allowed, while all requests from the other public IP addresses were rejected.
Traffic between ECS instances
Parameter | Intra-VPC traffic | Inter-VPC traffic |
Diagram | ||
Description | Assume you have deployed three ECS instances in one VPC, and the instances communicate with each other. In this case, you can use flow logs to analyze the traffic rate and trends between the ECS instances. | A peering connection links two VPCs in different regions. You are billed for the cross-region traffic using the pay-as-you-go Cloud Data Transfer (CDT) model. You notice a recent, unexpected increase in your cross-region data transfer costs. In this case, use flow logs to identify which ECS instances generate the most traffic and help you optimize costs. |
Flow log configuration |
|
|
Query and analysis statement | Query the traffic rate trends between ECS1 and other ECS instances: | Query the session traffic rate trends between the two VPCs: |
Result preview | On the query and analysis results page, select the Graph tab and set the chart type to Area Chart. Set the x-axis field to time, the y-axis field to bandwidth, and the aggregation column to src_to_dst. Set the format unit to bps,Kbps,Mbps(bit). The traffic rate from 10.0.0.1 to 10.0.0.2 is the highest at approximately 1.4 Mbps. The rate from 10.0.0.1 to 10.0.0.3 is the second highest at approximately 700 Kbps. The remaining traffic is minimal. | The visualization configuration is the same as the intra-VPC scenario. Select the Area Chart type and set the aggregation column to src_to_dst. Traffic from 10.0.0.1 to 172.16.0.1 spikes to approximately 6 Mbps. |
Internet NAT Gateway traffic
In this scenario, you have multiple ECS instances deployed in the same region and vSwitch. These instances use the SNAT feature of an Internet NAT Gateway to access the Internet.
You notice a recent surge in traffic from the Internet NAT Gateway to the Internet, which causes slow server responses. You can use flow logs to identify the ECS instances responsible for most of this traffic.
Create a flow log
For Resource Instance, select
vSwitch 2, the vSwitch where the Internet NAT Gateway is located.For delivery settings, select Deliver to Log Service and enable the Enable Log Analysis Report.
Keep the default values for other settings.
Filter specific traffic paths
To filter traffic on specific paths in this scenario, you must specify different conditions in your query statement:
Diagram
Number
Filter method
①
Filter traffic from an ECS instance to the NAT gateway: The
directionis in, and thesrcaddris the private IP address of the ECS instance.②
Filter traffic from the NAT gateway to the Internet: The
directionis out, and thesrcaddris the private IP address of the NAT gateway.③
Filter traffic from the Internet to the NAT gateway: The
directionis in, and thedstaddris the private IP address of the NAT gateway.④
Filter traffic from the NAT gateway to an ECS instance: The
directionis out, and thedstaddris the private IP address of the ECS instance.Analyze the flow logs
Query and analysis statement
On the path from an ECS instance to the NAT gateway, analyze traffic to a specific public IP address:
direction: 'in' and srcaddr: 10.0.0.* and dstaddr: 120.26.XX.XX | select -- Filter for logs of ECS instances accessing a specific public IP address date_format(from_unixtime(__time__ - __time__% 60), '%H:%i:%S') as time, srcaddr, -- Convert the Unix timestamp to a readable time format sum(bytes*8/60) as bandwidth -- Calculate bandwidth in bit/s by converting bytes to bits and dividing by the 60-second capture window group by time,srcaddr -- Group results by time and source IP order by time asc -- Sort by time in ascending order limit 100 -- Return the first 100 resultsResult preview
The visualization configuration is similar to the ECS traffic scenario. Select the Area Chart type and set the aggregation column to srcaddr.
On the path from ECS instances to the NAT gateway, the traffic rate from 10.0.0.1 (ECS1) to the public IP address 120.26.XX.XX is the highest, at approximately 12 Kbps.
Express Connect traffic distribution
In this scenario, a company uses two VPCs in an Alibaba Cloud region to deploy different services. The company connects its on-premises data center to Alibaba Cloud using an Express Connect circuit and CEN.
The IT department wants to use flow logs to monitor and analyze how traffic from different services in the VPCs uses the Express Connect circuit's resources. This analysis helps with network resource planning and performance improvements.
Create flow logs
Create two flow logs that deliver data to the same Logstore. Configure the key parameters for each flow log as follows:
For Resource Instance, select VPC and then select VPC1 and VPC2 respectively.
For Sampling Path, select Transit Router.
For delivery settings, select Deliver to Log Service, choose the same Logstore for both flow logs, and enable the Enable Log Analysis Report.
Keep the default values for other settings.
Analyze the flow logs
Query and analysis statement
Analyze the percentage of traffic from each VPC to the on-premises data center:
action: ACCEPT and srcaddr: 192.168.* and dstaddr:10.1.* | WITH vpc1_traffic AS ( SELECT date_trunc('minute',__time__) AS minute, SUM(bytes*8/(case WHEN "end"-start=0 THEN 1 else "end"-start end)) AS total_vpc1_traffic FROM log WHERE srcaddr LIKE '192.168.20.%' GROUP BY date_trunc('minute',__time__) ), vpc2_traffic AS ( SELECT date_trunc('minute',__time__) AS minute, SUM(bytes*8/(case WHEN "end"-start=0 THEN 1 else "end"-start end)) AS total_vpc2_traffic FROM log WHERE srcaddr LIKE '192.168.10.%' GROUP BY date_trunc('minute',__time__) ) SELECT COALESCE(vpc1_traffic.minute, vpc2_traffic.minute) AS minute, (COALESCE(vpc1_traffic.total_vpc1_traffic, 0) * 100/ NULLIF((COALESCE(vpc1_traffic.total_vpc1_traffic, 0) + COALESCE(vpc2_traffic.total_vpc2_traffic, 0)), 0)) AS vpc1_percentage, (COALESCE(vpc2_traffic.total_vpc2_traffic, 0) * 100/ NULLIF((COALESCE(vpc1_traffic.total_vpc1_traffic, 0) + COALESCE(vpc2_traffic.total_vpc2_traffic, 0)), 0)) AS vpc2_percentage FROM vpc1_traffic FULL OUTER JOIN vpc2_traffic ON vpc1_traffic.minute = vpc2_traffic.minute ORDER BY minuteResult preview
The visualization configuration is similar to the ECS traffic scenario. Select the Area Chart type to display the traffic percentage trends from different VPCs over time.
During the period from 14:50 to 15:50, VPC1 generated a higher percentage of the traffic to the on-premises data center.
More information
Flow log fields
The following table describes the fields in a flow log record.
If a field is not applicable, the field value is displayed as -.Parameter | Description |
version | The flow log version. The current version is |
account-id | The ID of the Alibaba Cloud account. |
eni-id | The ID of the elastic network interface. |
vm-id | The ID of the ECS instance to which the elastic network interface is attached. |
vswitch-id | The ID of the vSwitch to which the elastic network interface belongs. |
vpc-id | The ID of the VPC to which the elastic network interface belongs. |
type | The IP version of the traffic. Valid values are IPv4 and IPv6. The following regions support Dual-stack traffic capture: China (Hangzhou), China (Shanghai), China (Qingdao), China (Beijing), China (Hohhot), China (Shenzhen), Singapore, US (Silicon Valley), and US (Virginia). |
protocol | The IANA protocol number for the traffic. For example, 1 for ICMP, 6 for TCP, and 17 for UDP. |
srcaddr | The source IP address. |
srcport | The source port. |
dstaddr | The destination IP address. |
dstport | The destination port. |
direction | The direction of the traffic:
|
action | The action taken on the traffic, as determined by a security group or network ACL:
|
packets | The number of packets. |
bytes | The number of bytes. |
start | The time when the first packet was received during the capture window, in Unix timestamp format. |
end | For long-lived connections, this is the end of the capture window. For short-lived connections, it is the time the connection was closed. The value is in Unix timestamp format. |
tcp-flags | TCP flags, represented in decimal, reflect the combination of TCP flags supported by flow logs. A single flow log entry within a capture window may correspond to multiple TCP packets. This value is the result of a For example, if a TCP session has two packets within a capture window, carrying SYN (2) and SYN-ACK (18) flags respectively, the TCP flags field recorded in the log is 18 (2 | 18 = 18). Decimal values of supported TCP flags:
Unsupported flags are handled as follows:
For details on TCP flags, such as the meaning of SYN, FIN, ACK, and RST, see RFC 793. |
log-status | The logging status of the flow log record:
|
traffic_path | The scenario in which the traffic was captured:
|
The following sections provide examples of flow log records:
Allowed traffic record
In this example, the Alibaba Cloud account ID is 1210123456******, and the flow log version is 1. During the 1-minute capture window from 17:10:20 to 17:11:20 on July 12, 2024, the elastic network interface eni-bp166tg9uk1ryf****** allowed the following outbound traffic:
The source at 172.31.16.139 on port 1332 sent 10 packets to the destination at 172.31.16.21 on port 80 over TCP (protocol number 6). The total size of the packets was 2,048 bytes. The log status is OK.
{
"account-id": "1210123456******",
"action": "ACCEPT",
"bytes": "2048",
"direction": "out",
"dstaddr": "172.31.16.21",
"dstport": "80",
"end": "1720775480",
"eni-id": "eni-bp166tg9uk1ryf******",
"log-status": "OK",
"packets": "10",
"protocol": "6",
"srcaddr": "172.31.16.139",
"srcport": "1332",
"start": "1720775420",
"tcp-flags": "22",
"traffic_path": "-",
"version": "-",
"vm-id": "1",
"vpc-id": "-",
"vswitch-id": "vpc-bp1qf0c43jb3maz******"
}Rejected traffic record
In this example, the Alibaba Cloud account ID is 1210123456******, and the flow log version is 1. During the 10-minute capture window from 10:20:00 to 10:30:00 on July 15, 2024, the elastic network interface eni-bp1ftp5sm9oszt****** rejected the following inbound traffic:
The source at 172.31.16.139 on port 1332 attempted to send 20 packets to the destination at 172.31.16.21 on port 80 over TCP (protocol number 6). The total size of the packets was 4,208 bytes. The log status is OK.
{
"account-id": "1210123456******",
"action": "REJECT",
"bytes": "4208",
"direction": "in",
"dstaddr": "172.31.16.21",
"dstport": "80",
"end": "1721010600",
"eni-id": "eni-bp1ftp5sm9oszt******",
"log-status": "OK",
"packets": "20",
"protocol": "6",
"srcaddr": "172.31.16.139",
"srcport": "1332",
"start": "1721010000",
"tcp-flags": "22",
"traffic_path": "-",
"version": "-",
"vm-id": "1",
"vpc-id": "-",
"vswitch-id": "vpc-bp1qf0c43jb3maz******"
}No data record
In this example, the Alibaba Cloud account ID is 1210123456******, and the flow log version is 1. During the 3-minute capture window from 10:52:20 to 10:55:20 on July 15, 2024, no traffic data (NODATA) was recorded for the elastic network interface eni-bp1j7mmp34jlve******.
{
"account-id": "1210123456******",
"action": "-",
"bytes": "-",
"direction": "-",
"dstaddr": "-",
"dstport": "-",
"end": "1721012120",
"eni-id": "eni-bp1j7mmp34jlve******",
"log-status": "NODATA",
"packets": "-",
"protocol": "-",
"srcaddr": "-",
"srcport": "-",
"start": "1721011940",
"tcp-flags": "-",
"traffic_path": "-",
"version": "-",
"vm-id": "1",
"vpc-id": "-",
"vswitch-id": "vpc-bp1qf0c43jb3maz******"
}Skipped data record
In this example, the Alibaba Cloud account ID is 1210123456******, and the flow log version is 1. During the 3-minute capture window from 16:20:30 to 16:23:30 on July 12, 2024, data records for the elastic network interface eni-bp1dfm4xnlpruv****** were skipped (SKIPDATA).
{
"account-id": "1210123456******",
"action": "-",
"bytes": "-",
"direction": "-",
"dstaddr": "-",
"dstport": "-",
"end": "1720772610",
"eni-id": "eni-bp1dfm4xnlpruv******",
"log-status": "SKIPDATA",
"packets": "-",
"protocol": "-",
"srcaddr": "-",
"srcport": "-",
"start": "1720772430",
"tcp-flags": "-",
"traffic_path": "-",
"version": "-",
"vm-id": "1",
"vpc-id": "-",
"vswitch-id": "vpc-bp1qf0c43jb3maz******"
}Billing
Billable items
You are charged for flow logs based on the following items: log generation fees, Simple Log Service (SLS) fees, and, if enabled, Traffic Analyzer fees for traffic processing and storage.
Log generation fees:
The billing cycle is one hour. Bills are typically generated three to four hours after a billing cycle ends, though the actual time may vary.
Log generation fees are calculated based on a tiered pricing model for the monthly volume of logs generated in each region. Each Alibaba Cloud account receives a free quota of 5 GB per month in each region.
Monthly log volume
Price (USD/GB)
0 TB to 10 TB (inclusive)
0.37
10 TB to 30 TB (inclusive)
0.185
30 TB to 50 TB (inclusive)
0.074
More than 50 TB
0.037
Simple Log Service (SLS) fees: Charged by SLS after flow logs are delivered. This includes fees for data writes and storage.
SLS offers two billing methods: pay-by-data-volume and pay-by-feature. If you create a flow log in the VPC console and choose to create a new Logstore, the pay-by-feature billing method is used by default.
Traffic Analyzer fees: Charged by Network Intelligence Service (NIS) after flow logs are delivered to Traffic Analyzer. This includes traffic processing and storage fees.
Billing examples
Example 1
Assume you enable the flow log feature in a region at 00:00:00 on September 1, 2022. Between then and 00:00:00 on October 1, 2022, you deliver a total of 3 GB of logs to Simple Log Service (SLS).
Because each Alibaba Cloud account has a free monthly quota of 5 GB for log generation fees, your total flow log fee for the month consists only of SLS fees.
Example 2
Assume you enable the flow log feature in the China (Shanghai) region at 00:00:00 on September 1, 2022. Between then and 00:00:00 on October 1, 2022, you deliver 100 GB of logs to Simple Log Service (SLS).
The log generation fee for the month is (100 - 5) × 0.37 = USD 35.15. The total flow log fee for the month is USD 35.15 + SLS fees.
Example 3
Assume you enable the flow log feature in the China (Beijing) region at 00:00:00 on September 1, 2022. Between then and 00:00:00 on October 1, 2022, you deliver 60 TB of logs to Simple Log Service (SLS).
The log generation fee is calculated based on the tiered pricing model:
0 to 10 TB (inclusive): (10 × 1024 - 5) × 0.37 = USD 3,786.95
10 to 30 TB (inclusive): 20 × 1024 × 0.185 = USD 3,788.8
30 to 50 TB (inclusive): 20 × 1024 × 0.074 = USD 1,515.52
More than 50 TB: 10 × 1024 × 0.037 = USD 378.88
The total log generation fee for the month is 3,786.95 + 3,788.8 + 1,515.52 + 378.88 = USD 9,470.15. The total flow log fee for the month is USD 9,470.15 + SLS fees.
Overdue payments and top-ups
Supported regions
Area | Regions |
Asia Pacific - China | China (Hangzhou), China (Shanghai), China (Qingdao), China (Beijing), China (Zhangjiakou), China (Hohhot), China (Ulanqab), China (Shenzhen), China (Heyuan), China (Guangzhou), China (Chengdu), China (Hong Kong), and China (Fuzhou - Local Region, Closing Down) |
Asia Pacific - Others | Japan (Tokyo), South Korea (Seoul), Singapore, Malaysia (Kuala Lumpur), Indonesia (Jakarta), Philippines (Manila), and Thailand (Bangkok) |
Europe & Americas | Germany (Frankfurt), UK (London), US (Silicon Valley), and US (Virginia) |
Middle East | UAE (Dubai), and SAU (Riyadh - Partner Region) |
Quotas
Quota name | Description | Default limit | Adjustable |
vpc_quota_flowlog_inst_nums_per_user | The maximum number of flow log instances that a user can create. | 10 | Yes. To request a quota increase, go to the Quota Management page or Quota Center. |
FAQ
How long are VPC flow logs retained?
After flow logs are generated, they are automatically delivered to Simple Log Service (SLS) and are subject to its data retention policy.
If you select Enable Log Analysis Report when you create a flow log, the default data retention period for the Logstore is 7 days. Otherwise, the default retention period is 300 days.
You can modify the data retention period for an existing Logstore in the SLS console as needed.