All Products
Search
Document Center

Virtual Private Cloud:VPC flow log

Last Updated:Sep 18, 2026

VPC flow logs capture inbound and outbound traffic for elastic network interfaces (ENIs). Use flow logs to monitor network performance, troubleshoot network faults, and optimize traffic costs.

How it works

image

You can create flow logs to capture traffic at three levels of granularity: an elastic network interface (ENI), a vSwitch, or a VPC. If you create a flow log for a VPC or a vSwitch, the system captures traffic from all associated ENIs, including any ENIs created later.

During each capture window, which is 10 minutes by default, the system aggregates traffic data into flow log entries and delivers them to Simple Log Service.

Each flow log entry captures a specific 5-tuple network flow for a capture window. The entry includes fields for the source and destination IP addresses, source and destination ports, and the protocol. For example:

Eni-id

Direction

Srcaddr

Srcport

Protocol

Dstaddr

Dstport

...

eni-xxx

in

10.0.0.1

53870

6

10.0.0.2

80

...

eni-xxx

out

10.0.0.2

80

6

10.0.0.1

53870

...

For a description of all fields, see Flow log fields.

To reduce costs, you can capture traffic only from specific paths. Available paths include:

  • Traffic to the internet through an IPv4 gateway

  • Traffic through a NAT Gateway

  • Traffic through a VPN Gateway

  • Traffic through a Transit Router (TR)

  • Traffic to a cloud service through a gateway endpoint

  • Traffic to an Express Connect circuit through a virtual border router (VBR)

  • Traffic through an Express Connect Router (ECR)

  • Traffic through a Gateway Load Balancer endpoint

  • Traffic to the internet

    Capturing traffic from an Internet-facing Classic Load Balancer (CLB) to the internet is not supported.

Common use cases for flow logs include:

  • Network monitoring: Monitor VPC throughput and performance, analyze traffic patterns and trends for resources within a VPC, troubleshoot network issues, and verify that security group and network ACL rules are working as expected.

  • Network cost optimization: Analyze network traffic to optimize your data transfer costs. For example, you can identify traffic from a VPC to other regions, to specific public IP addresses, or to on-premises data centers and other cloud networks. You can also locate ECS instances within your VPC that generate significant traffic.

  • Security analysis: During a security incident, you can analyze inbound and outbound traffic to identify suspicious IP addresses or investigate access from malicious IPs.

Limitations

  • To use flow logs for the first time, you must:

    • On the Flow log, click Activate Now. If you created flow log instances during the public preview, you must still click Activate Now to view and manage these instances.

    • On the Flow log, click Authorize Now, and then click Authorize. This action automatically creates a RAM role named AliyunVPCLogArchiveRole and a RAM policy named AliyunVPCLogArchiveRolePolicy. VPC uses this role and policy by default to access Simple Log Service and write flow logs to it.

    • Activate Simple Log Service on the Simple Log Service product page.

  • After you enable flow logs, the initial traffic capture for a new elastic network interface may be delayed, typically by less than 10 minutes.

  • Flow logs do not capture multicast traffic.

  • When customizing subscription fields, you must subscribe to at least one field. If you also deliver logs to NIS Traffic Analyzer, the subscription must meet the NIS minimum required field set validation rules.

Manage flow logs

Console

Create a flow log

Go to the Flow log in the VPC console and click Create a flow log. In the Create a flow log panel, configure the following parameters:

  1. Collection Configuration:

    1. Region: Select the region of the target resource.

    2. Resource Type and Resource Instance: Select the collection granularity. You can select VPC, vSwitch, or ENI. If you select a VPC or vSwitch, the system monitors traffic for all ENIs within the selected resource.

    3. Data Transfer Type: Select whether to capture traffic that is allowed or rejected by access controls, such as security group and network ACL rules.

    4. IP Version: Select IPv4 to capture only IPv4 traffic, or select Dual-stack to capture both IPv4 and IPv6 traffic. The following regions support IPv6: China (Hangzhou), China (Shanghai), China (Qingdao), China (Beijing), China (Hohhot), China (Shenzhen), Singapore, US (Silicon Valley), and US (Virginia).

    5. Sampling Interval (Minutes): Specifies the duration of the capture window for aggregating traffic information. You can set the interval to 1, 5, or 10 minutes. A shorter interval generates flow logs more frequently and provides more timely data, which helps you detect and locate issues faster. A longer interval provides less timely data but reduces the number of log entries and helps save costs.

      For example, for a TCP session that maintains a persistent connection, a 1-minute window produces 60 log entries per hour, while a 10-minute window produces only 6 log entries.

      If multiple flow log instances in a VPC collect traffic from the same ENI, the system uses the shortest sampling interval among all instances as the actual capture period.
    6. Sampling Path: To reduce costs, you can select specific capture scenarios. To select a specific scenario, first deselect the default All Scenarios option.

      You can capture traffic that passes through the following network components: an IPv4 gateway, a NAT Gateway, a VPN Gateway, a Transit Router (TR), a gateway endpoint, a virtual border router (VBR), an Express Connect Router (ECR), a Gateway Load Balancer (GWLB) Endpoint, and traffic to the Internet.

  2. Analysis and Delivery: You can deliver logs to Log Service (SLS) and NIS Traffic Analyzer. You can deliver logs to Log Service only when you create the flow log. If you disable this feature, you cannot re-enable it.

    • Deliver to Log Service:

      • Select a project and Logstore: When you create your first flow log, we recommend that you click Create Project and Create Logstore to isolate the data. To consolidate multiple flow logs for centralized analysis, select the same Logstore.

      • Enable Log Analysis Report: We recommend that you select this option. This feature automatically creates an index and a dashboard for the Logstore that contains your flow logs, allowing you to perform SQL queries and visual analysis on the logs. After you enable this feature, charges are incurred for using Log Service (SLS).

    • Enable NIS Traffic Analysis: Select NIS Traffic Analyzer to perform traffic analysis. If the selection list is empty, you must first Create NIS Traffic Analyzer. Ensure that the NIS Traffic Analyzer that you create or select has a The sampling interval of the traffic analyzer must be greater than that of the flow log.

      Supported regions for integrating VPC flow logs with an NIS Traffic Analyzer.

  3. After you create the flow log, the system automatically starts to capture traffic. You can then analyze flow logs.

Start or stop a flow log

On the Flow log in the VPC console, find the target flow log and click Start or Stop in the Actions column.

After you stop a flow log, you are no longer charged for generating flow logs. However, Log Service (SLS) continues to bill you for storing the existing flow logs.

Delete a flow log

On the Flow log in the VPC console, find the target flow log and click Delete in the Actions column.

After you delete a flow log, you are no longer charged for generating flow logs. However, Log Service (SLS) continues to Billing. To stop all charges, go to the Log Service console and Manage Logstores.

API

Before creating a flow log, ensure you have enabled the flow log feature and created a project and Logstore in Log Service (SLS):

After meeting these prerequisites, you can perform the following operations:

Terraform

Resources: alicloud_log_project, alicloud_log_store, alicloud_vpc_flow_log
# Specify the region where you want to create the flow log.
provider "alicloud" {
  region = "cn-hangzhou"
}

# Specify the description of the project and the names of the Logstore and flow log.
variable "name" {
  default = "vpc-flowlog-example"
}

# Generate a random string to use in the project name.
resource "random_uuid" "example" {
}

# Create a Log Service project.
resource "alicloud_log_project" "example" {
  project_name = substr("tf-example-${replace(random_uuid.example.result, "-", "")}", 0, 16)
  description  = var.name
}

# Create a Log Service Logstore.
resource "alicloud_log_store" "example" {
  project_name          = alicloud_log_project.example.project_name
  logstore_name         = var.name
  shard_count           = 3
  auto_split            = true
  max_split_shard_count = 60
  append_meta           = true
}

# Create a VPC flow log.
resource "alicloud_vpc_flow_log" "example" {
  flow_log_name        = var.name
  log_store_name       = alicloud_log_store.example.logstore_name
  description          = var.name
  traffic_path         = ["all"] # Capture traffic from all scenarios.
  project_name         = alicloud_log_project.example.project_name
  resource_type        = "VPC" # Resource type.
  resource_id          = "vpc-bp1ekmgzch0bo3hxXXXXXX" # VPC ID.
  aggregation_interval = "1" # Aggregation interval in minutes.
  traffic_type         = "All" # Capture all allowed and rejected traffic.
}

Analyze flow logs

Analyzing flow logs helps you monitor network performance, troubleshoot network issues, optimize traffic costs, and analyze network security.

Console

Custom analysis in a Logstore

Go to the Flow log in the VPC console. In the Simple Log Service column of the target flow log, click the Logstore name to open the Logstore details page. On this page, you can:

The Logstore query interface provides three tabs: Raw Logs, Graph, and Log Clustering. You can set the query time range. The upper area displays a timeline chart of log volume distribution, and the lower area displays a table of query results with fields such as srcaddr, dstaddr, and protocol.

Analysis with preset templates

The Flow Log Center provides visualization templates to quickly analyze VPC flow logs. The templates support VPC policy statistics, elastic network interface traffic statistics, and traffic statistics between CIDR blocks.

  1. Go to the Flowlog center page and click Add in the upper-right corner.

  2. In the Create Instance panel, enter an Instance Name, select the Project and Logstore that contain the existing flow log, and click OK.

  3. After the instance is created, click its instance ID in the Flow Log Center. On the Flow Log Details page, you can view and analyze the flow logs.

    The Monitoring Center provides the following dashboards and custom query features:

    • Overview: Displays accept and reject trends for flow logs, inbound and outbound traffic trends, the total number of packets and bytes for each VPC and elastic network interface (ENI), and the geographic distribution of source and destination IP addresses.

    • Policy Statistics: Displays Accept and Reject trends, and statistics for the number of accepted and rejected events based on the 5-tuple. A 5-tuple consists of a source IP address, source port, protocol type, destination IP address, and destination port.

      • Accept: Traffic that is allowed by security groups and network ACLs.

      • Reject: Traffic that is rejected by security groups and network ACLs.

    • ENI Traffic: Displays inbound and outbound traffic information for elastic network interfaces.

    • Inter-ECS Traffic: Displays traffic between ECS instances.

    • Custom Query: You can write your own queries. For instructions, see Quick guide to queries and analysis.

  4. Enable inter-domain analysis (optional): On the Flow Log Details page, click CIDR Block Settings. On the CIDR Block Settings tab, turn on the Inter-Domain Analysis switch.

    After you enable the inter-domain analysis feature, the system automatically creates a data transformation task. This task generates VPC flow logs that include CIDR block information for analyzing traffic between different CIDR blocks. The data transformation feature incurs charges.

    Simple Log Service provides multiple predefined CIDR blocks. To analyze traffic between different CIDR blocks, you can enable the inter-domain analysis feature with a single click. You can also add custom CIDR blocks as needed.

    Three types of CIDR blocks are predefined by default: Private network (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16 - adjustable based on your actual configuration), Alibaba Cloud services (partial) (100:64.0.0/10), and Internet (all CIDR blocks other than those listed above). Each CIDR block type supports edit and delete operations.

    The Inter-domain Analysis feature provides the following dashboards and custom query features:

    • Inter-domain Traffic: Displays traffic between different CIDR blocks.

    • ECS-to-Domain Traffic: Displays traffic from ECS instances to destination CIDR blocks.

    • Threat Intelligence: Displays threat intelligence for source and destination IP addresses.

    • Custom Query: You can write queries to query and analyze VPC flow logs that contain CIDR block information.

API

Call GetLogsV2 to query and analyze flow logs.

Examples

This topic provides four examples of common use cases.

Source IPs for public access

image

In this scenario, you have a web server that is accessible from the Internet and listens on port 80. You have also configured security group rules to control access from specific source IPs.

By creating a flow log, you can identify the source IPs that access port 80 and determine how many of their requests your security group rules allow or reject.

  1. Create a flow log

    • For Resource Instance, select the ENI of the web server.

    • For Data Transfer Type, select All Traffic.

    • For delivery settings, select Deliver to Log Service and enable the Enable Log Analysis Report.

    • Keep the default values for other settings.

  2. Analyze the flow logs

    1. Query and analysis statement

      Filter for traffic to port 80 on the server at 10.0.0.1, and display the number of times each source IP was allowed or rejected by the security group:

      dstaddr:10.0.0.1 AND dstport:80 | SELECT -- Filter for logs where the destination IP is 10.0.0.1 and the destination port is 80
      srcaddr,
      SUM(CASE WHEN action = 'ACCEPT' THEN 1 ELSE 0 END) AS accept_count, -- Count 1 for each 'ACCEPT' (allowed) action
      SUM(CASE WHEN action = 'REJECT' THEN 1 ELSE 0 END) AS reject_count -- Count 1 for each 'REJECT' (rejected) action
      FROM log
      GROUP BY srcaddr -- Group the results by source IP address
      ORDER BY accept_count + reject_count DESC -- Sort results in descending order by the total number of allowed and rejected connections
    2. Result preview

      The srcaddr column lists the source IPs that accessed port 80. The accept_count and reject_count columns show how many times the security group allowed or rejected connections from each source IP during the specified time range:

      • Five source IPs accessed port 80: 120.26.XX.XX, 121.43.XX.XX, 154.212.XX.XX, 176.65.XX.XX, and 198.235.XX.XX.

      • All requests from 120.26.XX.XX were allowed, while all requests from the other public IP addresses were rejected.

Traffic between ECS instances

Parameter

Intra-VPC traffic

Inter-VPC traffic

Diagram

imageimage

Description

Assume you have deployed three ECS instances in one VPC, and the instances communicate with each other.

In this case, you can use flow logs to analyze the traffic rate and trends between the ECS instances.

A peering connection links two VPCs in different regions. You are billed for the cross-region traffic using the pay-as-you-go Cloud Data Transfer (CDT) model.

You notice a recent, unexpected increase in your cross-region data transfer costs. In this case, use flow logs to identify which ECS instances generate the most traffic and help you optimize costs.

Flow log configuration

  • For Resource Instance, select the ENI of ECS1.

  • For Analysis and Delivery, select Deliver to Log Service and enable the Enable Log Analysis Report.

  • Keep the default values for other settings.

  • For Resource Instance, select VPC VPC1.

  • For Analysis and Delivery, select Deliver to Log Service and enable the Enable Log Analysis Report.

  • Keep the default values for other settings.

Query and analysis statement

Query the traffic rate trends between ECS1 and other ECS instances:

(srcaddr:10.0.0.1 AND dstaddr:10.0.0.*) OR (srcaddr:10.0.0.* AND dstaddr:10.0.0.1 )  | select -- Filter for traffic trends between ECS1 and other ECS instances
date_format(from_unixtime(__time__ - __time__% 60), '%H:%i:%S') as time, -- Convert the Unix timestamp to a readable time format
concat(srcaddr,'->', dstaddr) as src_to_dst, -- Create a session pair in the format 'source_ip->destination_ip'
sum(bytes*8/60) as bandwidth -- Calculate bandwidth in bit/s by converting bytes to bits and dividing by the 60-second capture window
group by time,srcaddr,dstaddr -- Group results by time, source IP, and destination IP
order by time asc  -- Sort by time in ascending order
limit 100 -- Return the first 100 results

Query the session traffic rate trends between the two VPCs:

(srcaddr:10.0.* AND dstaddr:172.16.*) OR (srcaddr:172.16.* AND dstaddr:10.0.*)  | select -- Filter for sessions between the two VPCs
date_format(from_unixtime(__time__ - __time__% 60), '%H:%i:%S') as time, -- Convert the Unix timestamp to a readable time format
concat(srcaddr,'->', dstaddr) as src_to_dst, -- Create a session pair in the format 'source_ip->destination_ip'
sum(bytes*8/60) as bandwidth -- Calculate bandwidth in bit/s by converting bytes to bits and dividing by the 60-second capture window
group by time,srcaddr,dstaddr -- Group results by time, source IP, and destination IP
order by time asc  -- Sort by time in ascending order
limit 100 -- Return the first 100 results

Result preview

On the query and analysis results page, select the Graph tab and set the chart type to Area Chart. Set the x-axis field to time, the y-axis field to bandwidth, and the aggregation column to src_to_dst. Set the format unit to bps,Kbps,Mbps(bit).

The traffic rate from 10.0.0.1 to 10.0.0.2 is the highest at approximately 1.4 Mbps. The rate from 10.0.0.1 to 10.0.0.3 is the second highest at approximately 700 Kbps. The remaining traffic is minimal.

The visualization configuration is the same as the intra-VPC scenario. Select the Area Chart type and set the aggregation column to src_to_dst.

Traffic from 10.0.0.1 to 172.16.0.1 spikes to approximately 6 Mbps.

Internet NAT Gateway traffic

image

In this scenario, you have multiple ECS instances deployed in the same region and vSwitch. These instances use the SNAT feature of an Internet NAT Gateway to access the Internet.

You notice a recent surge in traffic from the Internet NAT Gateway to the Internet, which causes slow server responses. You can use flow logs to identify the ECS instances responsible for most of this traffic.

  1. Create a flow log

    • For Resource Instance, select vSwitch 2, the vSwitch where the Internet NAT Gateway is located.

    • For delivery settings, select Deliver to Log Service and enable the Enable Log Analysis Report.

    • Keep the default values for other settings.

  2. Filter specific traffic paths

    To filter traffic on specific paths in this scenario, you must specify different conditions in your query statement:

    Diagram

    Number

    Filter method

    image

    ①

    Filter traffic from an ECS instance to the NAT gateway: The direction is in, and the srcaddr is the private IP address of the ECS instance.

    ②

    Filter traffic from the NAT gateway to the Internet: The direction is out, and the srcaddr is the private IP address of the NAT gateway.

    ③

    Filter traffic from the Internet to the NAT gateway: The direction is in, and the dstaddr is the private IP address of the NAT gateway.

    ④

    Filter traffic from the NAT gateway to an ECS instance: The direction is out, and the dstaddr is the private IP address of the ECS instance.

  3. Analyze the flow logs

    1. Query and analysis statement

      On the path from an ECS instance to the NAT gateway, analyze traffic to a specific public IP address:

      direction: 'in' and srcaddr: 10.0.0.* and dstaddr: 120.26.XX.XX | select -- Filter for logs of ECS instances accessing a specific public IP address
      date_format(from_unixtime(__time__ - __time__% 60), '%H:%i:%S') as time, srcaddr,  -- Convert the Unix timestamp to a readable time format
      sum(bytes*8/60) as bandwidth  -- Calculate bandwidth in bit/s by converting bytes to bits and dividing by the 60-second capture window
      group by time,srcaddr -- Group results by time and source IP
      order by time asc  -- Sort by time in ascending order
      limit 100 -- Return the first 100 results

      Other common queries

      • On the path from the NAT gateway to an ECS instance, filter inbound traffic from a specific public IP address to all ECS instances:

        direction: 'out' and dstaddr: 10.0.0.* and srcaddr: 120.26.XX.XX | select -- Filter for logs of ECS instances accessing a specific public IP address
        date_format(from_unixtime(__time__ - __time__% 60), '%H:%i:%S') as time,   -- Convert the Unix timestamp to a readable time format
        dstaddr,
        sum(bytes*8/60) as bandwidth  -- Calculate bandwidth in bit/s by converting bytes to bits and dividing by the 60-second capture window
        group by time,dstaddr -- Group results by time and destination IP
        order by time asc  -- Sort by time in ascending order
        limit 100 -- Return the first 100 results
      • On the path from an ECS instance to the NAT gateway, filter outbound traffic from the ECS instance to all public IP addresses:

        direction: 'in' and srcaddr: 10.0.0.*  | select -- Filter for logs of ECS instances accessing all public IP addresses
        date_format(from_unixtime(__time__ - __time__% 60), '%H:%i:%S') as time,  -- Convert the Unix timestamp to a readable time format
        concat(srcaddr,'->', dstaddr), -- Create a session pair in the format 'source_ip->destination_ip'
        sum(bytes*8/60) as bandwidth  -- Calculate bandwidth in bit/s by converting bytes to bits and dividing by the 60-second capture window
        group by time,srcaddr,dstaddr -- Group results by time, source IP, and destination IP
        order by time asc  -- Sort by time in ascending order
        limit 100 -- Return the first 100 results
    2. Result preview

      The visualization configuration is similar to the ECS traffic scenario. Select the Area Chart type and set the aggregation column to srcaddr.

      On the path from ECS instances to the NAT gateway, the traffic rate from 10.0.0.1 (ECS1) to the public IP address 120.26.XX.XX is the highest, at approximately 12 Kbps.

Express Connect traffic distribution

image

In this scenario, a company uses two VPCs in an Alibaba Cloud region to deploy different services. The company connects its on-premises data center to Alibaba Cloud using an Express Connect circuit and CEN.

The IT department wants to use flow logs to monitor and analyze how traffic from different services in the VPCs uses the Express Connect circuit's resources. This analysis helps with network resource planning and performance improvements.

  1. Create flow logs

    Create two flow logs that deliver data to the same Logstore. Configure the key parameters for each flow log as follows:

    • For Resource Instance, select VPC and then select VPC1 and VPC2 respectively.

    • For Sampling Path, select Transit Router.

    • For delivery settings, select Deliver to Log Service, choose the same Logstore for both flow logs, and enable the Enable Log Analysis Report.

    • Keep the default values for other settings.

  2. Analyze the flow logs

    1. Query and analysis statement

      Analyze the percentage of traffic from each VPC to the on-premises data center:

      action: ACCEPT and srcaddr: 192.168.* and dstaddr:10.1.* | 
      WITH 
          vpc1_traffic AS (
              SELECT 
                  date_trunc('minute',__time__) AS minute,
                  SUM(bytes*8/(case WHEN "end"-start=0 THEN 1 else "end"-start end)) AS total_vpc1_traffic
              FROM 
                  log
              WHERE 
                  srcaddr LIKE '192.168.20.%'
              GROUP BY 
                  date_trunc('minute',__time__)
          ),
          vpc2_traffic AS (
              SELECT 
                  date_trunc('minute',__time__) AS minute,
                  SUM(bytes*8/(case WHEN "end"-start=0 THEN 1 else "end"-start end)) AS total_vpc2_traffic
              FROM 
                  log
              WHERE 
                  srcaddr LIKE '192.168.10.%'
              GROUP BY 
                  date_trunc('minute',__time__)
          )
      SELECT 
          COALESCE(vpc1_traffic.minute, vpc2_traffic.minute) AS minute,
          (COALESCE(vpc1_traffic.total_vpc1_traffic, 0) * 100/ NULLIF((COALESCE(vpc1_traffic.total_vpc1_traffic, 0) + COALESCE(vpc2_traffic.total_vpc2_traffic, 0)), 0)) AS vpc1_percentage, 
          (COALESCE(vpc2_traffic.total_vpc2_traffic, 0) * 100/ NULLIF((COALESCE(vpc1_traffic.total_vpc1_traffic, 0) + COALESCE(vpc2_traffic.total_vpc2_traffic, 0)), 0)) AS vpc2_percentage
      FROM vpc1_traffic FULL OUTER JOIN vpc2_traffic ON vpc1_traffic.minute = vpc2_traffic.minute 
      ORDER BY minute

      The following provides a detailed explanation of the SQL statement.

      • Filter conditions:

        • srcaddr: 192.168.* filters for logs where the source address starts with 192.168..

        • dstaddr: 10.1.* filters for logs where the destination address starts with 10.1..

        • action: ACCEPT. Filters logs where the action field is ACCEPT.

      • Main query

        • Uses FULL OUTER JOIN to combine the results from vpc1_traffic and vpc2_traffic based on the minute field.

        • Calculates the percentage of traffic from each VPC for every minute:

          • vpc1_percentage represents the percentage of total traffic that originates from VPC1.

          • vpc2_percentage represents the percentage of total traffic that originates from VPC2.

        • The query results are sorted in ascending order by minute.

      • WITH subqueries:

        The SQL statement contains two subqueries, vpc1_traffic and vpc2_traffic. The following is an explanation of the vpc1_traffic subquery:

        • The date_trunc function truncates the Unix timestamp (the __time__ field) to the nearest minute, aliased as minute.

        • The SUM function calculates the total traffic rate in bit/s for each minute, aliased as total_vpc1_traffic.

        • Filters traffic records where the source address is in the 192.168.20.* CIDR block (VPC1).

        • Groups the results by minute.

    2. Result preview

      The visualization configuration is similar to the ECS traffic scenario. Select the Area Chart type to display the traffic percentage trends from different VPCs over time.

      During the period from 14:50 to 15:50, VPC1 generated a higher percentage of the traffic to the on-premises data center.

More information

Flow log fields

The following table describes the fields in a flow log record.

If a field is not applicable, the field value is displayed as -.

Parameter

Description

version

The flow log version. The current version is 1.

account-id

The ID of the Alibaba Cloud account.

eni-id

The ID of the elastic network interface.

vm-id

The ID of the ECS instance to which the elastic network interface is attached.

vswitch-id

The ID of the vSwitch to which the elastic network interface belongs.

vpc-id

The ID of the VPC to which the elastic network interface belongs.

type

The IP version of the traffic. Valid values are IPv4 and IPv6.

The following regions support Dual-stack traffic capture: China (Hangzhou), China (Shanghai), China (Qingdao), China (Beijing), China (Hohhot), China (Shenzhen), Singapore, US (Silicon Valley), and US (Virginia).

protocol

The IANA protocol number for the traffic. For example, 1 for ICMP, 6 for TCP, and 17 for UDP.

srcaddr

The source IP address.

srcport

The source port.

dstaddr

The destination IP address.

dstport

The destination port.

direction

The direction of the traffic:

  • in: Inbound traffic to the elastic network interface.

  • out: Outbound traffic from the elastic network interface.

action

The action taken on the traffic, as determined by a security group or network ACL:

  • ACCEPT: The traffic was allowed.

  • REJECT: The traffic was rejected.

packets

The number of packets.

bytes

The number of bytes.

start

The time when the first packet was received during the capture window, in Unix timestamp format.

end

For long-lived connections, this is the end of the capture window. For short-lived connections, it is the time the connection was closed. The value is in Unix timestamp format.

tcp-flags

TCP flags, represented in decimal, reflect the combination of TCP flags supported by flow logs.

A single flow log entry within a capture window may correspond to multiple TCP packets. This value is the result of a bitwise OR operation on the flag fields of all related packets.

For example, if a TCP session has two packets within a capture window, carrying SYN (2) and SYN-ACK (18) flags respectively, the TCP flags field recorded in the log is 18 (2 | 18 = 18).

Decimal values of supported TCP flags:

  • FIN: 1

  • SYN: 2

  • RST: 4

  • SYN-ACK: 18

Unsupported flags are handled as follows:

  • If a packet contains only unsupported flags, tcp-flags returns 0. For example, a packet carrying only the ACK flag has a tcp-flags value of 0.

  • If a packet contains both supported and unsupported flags, only the values of the supported flags are recorded; unsupported flags do not affect the result. For example, if a packet carries both SYN and ECE flags, since ECE is not supported, the tcp-flags value is 2, corresponding to SYN.

For details on TCP flags, such as the meaning of SYN, FIN, ACK, and RST, see RFC 793.

log-status

The logging status of the flow log record:

  • OK: Data was recorded successfully.

  • NODATA: No traffic was sent to or from the elastic network interface during the capture window. This can occur on standby systems, during non-peak hours, or due to configuration issues that cause a lack of traffic.

  • SKIPDATA: Some records were skipped during the capture window. This typically happens in high-traffic environments or during traffic spikes that overload the internal capture system.

traffic_path

The scenario in which the traffic was captured:

  • 0 - Traffic captured in scenarios other than those listed below.

  • 1 - Traffic that passes through other resources in the same VPC.

  • 2 - Private traffic to an ECS instance in the same VPC.

  • 3 - Traffic that passes through an elastic network interface.

  • 4 - Traffic that passes through a high-availability virtual IP address (HaVip).

  • 5 - Traffic to Alibaba Cloud services in the same region.

  • 6 - Traffic to cloud services through a gateway endpoint.

  • 7 - Traffic that passes through a NAT gateway.

  • 8 - Traffic that passes through a Transit Router (TR).

  • 9 - Traffic that passes through a VPN gateway.

  • 10 - Traffic to an Express Connect circuit through a Virtual Border Router (VBR).

  • 11 - Traffic to a VPC in the same region through Cloud Enterprise Network (CEN) Basic Edition.

  • 12 - Traffic through Cloud Enterprise Network (CEN) Basic Edition in scenarios other than those specified by codes 11, 18, 19, and 20. An example is traffic to cross-region cloud services through CEN Basic Edition.

  • 13 - Traffic to the internet through an IPv4 gateway.

  • 14 - Traffic to the internet through an IPv6 gateway.

  • 15 - Traffic to the internet from a public IP address.

  • 17 - Traffic over a VPC peering connection.

  • 18 - Traffic to a cross-region VPC through Cloud Enterprise Network (CEN) Basic Edition.

  • 19 - Traffic to a Virtual Border Router (VBR) in the same region through Cloud Enterprise Network (CEN) Basic Edition.

  • 20 - Traffic to a cross-region Virtual Border Router (VBR) through Cloud Enterprise Network (CEN) Basic Edition.

  • 21 - Traffic that passes through an Express Connect Router (ECR).

  • 22 - Traffic that passes through a Gateway Load Balancer endpoint.

The following sections provide examples of flow log records:

Allowed traffic record

In this example, the Alibaba Cloud account ID is 1210123456******, and the flow log version is 1. During the 1-minute capture window from 17:10:20 to 17:11:20 on July 12, 2024, the elastic network interface eni-bp166tg9uk1ryf****** allowed the following outbound traffic:

The source at 172.31.16.139 on port 1332 sent 10 packets to the destination at 172.31.16.21 on port 80 over TCP (protocol number 6). The total size of the packets was 2,048 bytes. The log status is OK.

{
  "account-id": "1210123456******",
  "action": "ACCEPT",
  "bytes": "2048",
  "direction": "out",
  "dstaddr": "172.31.16.21",
  "dstport": "80",
  "end": "1720775480",
  "eni-id": "eni-bp166tg9uk1ryf******",
  "log-status": "OK",
  "packets": "10",
  "protocol": "6",
  "srcaddr": "172.31.16.139",
  "srcport": "1332",
  "start": "1720775420",
  "tcp-flags": "22",
  "traffic_path": "-",
  "version": "-",
  "vm-id": "1",
  "vpc-id": "-",
  "vswitch-id": "vpc-bp1qf0c43jb3maz******"
}

Rejected traffic record

In this example, the Alibaba Cloud account ID is 1210123456******, and the flow log version is 1. During the 10-minute capture window from 10:20:00 to 10:30:00 on July 15, 2024, the elastic network interface eni-bp1ftp5sm9oszt****** rejected the following inbound traffic:

The source at 172.31.16.139 on port 1332 attempted to send 20 packets to the destination at 172.31.16.21 on port 80 over TCP (protocol number 6). The total size of the packets was 4,208 bytes. The log status is OK.

{
  "account-id": "1210123456******",
  "action": "REJECT",
  "bytes": "4208",
  "direction": "in",
  "dstaddr": "172.31.16.21",
  "dstport": "80",
  "end": "1721010600",
  "eni-id": "eni-bp1ftp5sm9oszt******",
  "log-status": "OK",
  "packets": "20",
  "protocol": "6",
  "srcaddr": "172.31.16.139",
  "srcport": "1332",
  "start": "1721010000",
  "tcp-flags": "22",
  "traffic_path": "-",
  "version": "-",
  "vm-id": "1",
  "vpc-id": "-",
  "vswitch-id": "vpc-bp1qf0c43jb3maz******"
}

No data record

In this example, the Alibaba Cloud account ID is 1210123456******, and the flow log version is 1. During the 3-minute capture window from 10:52:20 to 10:55:20 on July 15, 2024, no traffic data (NODATA) was recorded for the elastic network interface eni-bp1j7mmp34jlve******.

{
  "account-id": "1210123456******",
  "action": "-",
  "bytes": "-",
  "direction": "-",
  "dstaddr": "-",
  "dstport": "-",
  "end": "1721012120",
  "eni-id": "eni-bp1j7mmp34jlve******",
  "log-status": "NODATA",
  "packets": "-",
  "protocol": "-",
  "srcaddr": "-",
  "srcport": "-",
  "start": "1721011940",
  "tcp-flags": "-",
  "traffic_path": "-",
  "version": "-",
  "vm-id": "1",
  "vpc-id": "-",
  "vswitch-id": "vpc-bp1qf0c43jb3maz******"
}

Skipped data record

In this example, the Alibaba Cloud account ID is 1210123456******, and the flow log version is 1. During the 3-minute capture window from 16:20:30 to 16:23:30 on July 12, 2024, data records for the elastic network interface eni-bp1dfm4xnlpruv****** were skipped (SKIPDATA).

{
  "account-id": "1210123456******",
  "action": "-",
  "bytes": "-",
  "direction": "-",
  "dstaddr": "-",
  "dstport": "-",
  "end": "1720772610",
  "eni-id": "eni-bp1dfm4xnlpruv******",
  "log-status": "SKIPDATA",
  "packets": "-",
  "protocol": "-",
  "srcaddr": "-",
  "srcport": "-",
  "start": "1720772430",
  "tcp-flags": "-",
  "traffic_path": "-",
  "version": "-",
  "vm-id": "1",
  "vpc-id": "-",
  "vswitch-id": "vpc-bp1qf0c43jb3maz******"
}

Billing

Billable items

You are charged for flow logs based on the following items: log generation fees, Simple Log Service (SLS) fees, and, if enabled, Traffic Analyzer fees for traffic processing and storage.

image
  • Log generation fees:

    • The billing cycle is one hour. Bills are typically generated three to four hours after a billing cycle ends, though the actual time may vary.

    • Log generation fees are calculated based on a tiered pricing model for the monthly volume of logs generated in each region. Each Alibaba Cloud account receives a free quota of 5 GB per month in each region.

    Monthly log volume

    Price (USD/GB)

    0 TB to 10 TB (inclusive)

    0.37

    10 TB to 30 TB (inclusive)

    0.185

    30 TB to 50 TB (inclusive)

    0.074

    More than 50 TB

    0.037

  • Simple Log Service (SLS) fees: Charged by SLS after flow logs are delivered. This includes fees for data writes and storage.

    SLS offers two billing methods: pay-by-data-volume and pay-by-feature. If you create a flow log in the VPC console and choose to create a new Logstore, the pay-by-feature billing method is used by default.
  • Traffic Analyzer fees: Charged by Network Intelligence Service (NIS) after flow logs are delivered to Traffic Analyzer. This includes traffic processing and storage fees.

Billing examples

  • Example 1

    Assume you enable the flow log feature in a region at 00:00:00 on September 1, 2022. Between then and 00:00:00 on October 1, 2022, you deliver a total of 3 GB of logs to Simple Log Service (SLS).

    Because each Alibaba Cloud account has a free monthly quota of 5 GB for log generation fees, your total flow log fee for the month consists only of SLS fees.

  • Example 2

    Assume you enable the flow log feature in the China (Shanghai) region at 00:00:00 on September 1, 2022. Between then and 00:00:00 on October 1, 2022, you deliver 100 GB of logs to Simple Log Service (SLS).

    The log generation fee for the month is (100 - 5) × 0.37 = USD 35.15. The total flow log fee for the month is USD 35.15 + SLS fees.

  • Example 3

    Assume you enable the flow log feature in the China (Beijing) region at 00:00:00 on September 1, 2022. Between then and 00:00:00 on October 1, 2022, you deliver 60 TB of logs to Simple Log Service (SLS).

    The log generation fee is calculated based on the tiered pricing model:

    • 0 to 10 TB (inclusive): (10 × 1024 - 5) × 0.37 = USD 3,786.95

    • 10 to 30 TB (inclusive): 20 × 1024 × 0.185 = USD 3,788.8

    • 30 to 50 TB (inclusive): 20 × 1024 × 0.074 = USD 1,515.52

    • More than 50 TB: 10 × 1024 × 0.037 = USD 378.88

    The total log generation fee for the month is 3,786.95 + 3,788.8 + 1,515.52 + 378.88 = USD 9,470.15. The total flow log fee for the month is USD 9,470.15 + SLS fees.

Overdue payments and top-ups

Overdue payments and renewal policy

  • For up to 15 days after a payment becomes overdue, your instances continue to run without interruption.

  • If the bill is not paid within 15 days after the payment becomes overdue, the service is automatically stopped. After an instance is stopped, you can no longer manage it, and billing stops.

  • If you top up your account to pay the outstanding amount within 15 days of the instance being stopped, the service automatically resumes.

  • If you do not pay the outstanding amount within 15 days of the instance being stopped, the VPC flow log instance is automatically released. After an instance is released, its configuration and data are deleted and cannot be recovered.

Supported regions

Area

Regions

Asia Pacific - China

China (Hangzhou), China (Shanghai), China (Qingdao), China (Beijing), China (Zhangjiakou), China (Hohhot), China (Ulanqab), China (Shenzhen), China (Heyuan), China (Guangzhou), China (Chengdu), China (Hong Kong), and China (Fuzhou - Local Region, Closing Down)

Asia Pacific - Others

Japan (Tokyo), South Korea (Seoul), Singapore, Malaysia (Kuala Lumpur), Indonesia (Jakarta), Philippines (Manila), and Thailand (Bangkok)

Europe & Americas

Germany (Frankfurt), UK (London), US (Silicon Valley), and US (Virginia)

Middle East

UAE (Dubai), and SAU (Riyadh - Partner Region)

Quotas

Quota name

Description

Default limit

Adjustable

vpc_quota_flowlog_inst_nums_per_user

The maximum number of flow log instances that a user can create.

10

Yes. To request a quota increase, go to the Quota Management page or Quota Center.

FAQ

How long are VPC flow logs retained?

After flow logs are generated, they are automatically delivered to Simple Log Service (SLS) and are subject to its data retention policy.