AWS Shield Advanced introduces DDoS attack flow logs
News
This article announces DDoS attack flow logs for AWS Shield Advanced, providing packet-level visibility into DDoS attacks on protected resources.
- Packet-level visibility into traffic during DDoS attacks on Shield Advanced protected resources
- Log data published to S3, CloudWatch Logs, or Data Firehose for analysis
- Captures source/destination IPs, ports, protocols, packet/byte counts, source country information
- Logs published automatically at 5-minute intervals during active attacks
- Enables post-incident investigation, threat intelligence, and compliance reporting
- Available in all regions where AWS Shield Advanced is available
AWS Shield Advanced now provides detailed DDoS attack flow logs for forensic analysis and compliance purposes.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
Jun 4
2026
2026
Gain visibility into DDoS attacks with flow logs in AWS Shield Advanced
Apr 8
2022
2022
AWS Shield Advanced now supports Application Load Balancer for automatic application layer DDoS mitigation
Jul 27
2026
2026
AWS Shield Advanced is embracing the AWS WAF Anti-DDoS managed rule group: What changes and how to prepare
Jun 12
2025
2025
Introducing new application layer (L7) DDoS protections for AWS WAF and AWS Shield Advanced customers
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.