> Source: [sk144753](https://support.checkpoint.com/results/sk/sk144753)

# sk144753 - How to create a CloudGuard Flow Log for VPC or Subnet in AWS

| Property | Value |
|----------|-------|
| Solution ID | sk144753 |
| Date Created | 2019-01-16 |
| Last Modified | 2022-07-04 |
| Technical Level | General |
| Products | Cloud Firewall |
| Versions | R82.10, R81.20, R82 |

## Solution

Create a Flow Log for VPC or Subnet in AWS
==========================================

**Requirements:**

1. Create a Flow Logs Role
2. Create a Destination Log Group

Create a flow log for a VPC or a subnet
---------------------------------------

1. Open the Amazon VPC console at <https://console.aws.amazon.com/vpc/>.

2. In the navigation pane, choose **Your VPCs** , or choose **Subnets**.

3. Select your VPC or subnet, choose the **Flow Logs** tab, and then **Create Flow Log** .  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1547629278320/360004758033-Screen_Shot_2018-05-05_at_21901160105.02.50_PM.png)  
   Note:

   To create flow logs for multiple VPCs, choose the VPCs, and then select **Create Flow Log** from the **Actions** menu. To create flow logs for multiple subnets, choose the subnets, and then select **Create Flow Log** from the **Subnet Actions** menu.
4. In the dialog box, complete following information. When you are done, choose **Create Flow Log** :  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1547629278320/360004795754-Screen_Shot_2018-05-07_at_31901160111.30.46_PM.png)

   * **Filter**: Select whether the flow log should capture rejected traffic, accepted traffic, or all traffic.

   * **Role**: Specify the name of an IAM role that has permission to publish logs to CloudWatch Logs.

   * **Destination Log Group**: Enter the name of a log group in CloudWatch Logs to which the flow logs will be published. You can use an existing log group, or you can enter a name for a new log group, which we'll create for you.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
