Home icon

AWS Shield Advanced introduces DDoS attack flow logs

News



This article announces DDoS attack flow logs for AWS Shield Advanced, providing packet-level visibility into DDoS attacks on protected resources.

  • Packet-level visibility into traffic during DDoS attacks on Shield Advanced protected resources
  • Log data published to S3, CloudWatch Logs, or Data Firehose for analysis
  • Captures source/destination IPs, ports, protocols, packet/byte counts, source country information
  • Logs published automatically at 5-minute intervals during active attacks
  • Enables post-incident investigation, threat intelligence, and compliance reporting
  • Available in all regions where AWS Shield Advanced is available

AWS Shield Advanced now provides detailed DDoS attack flow logs for forensic analysis and compliance purposes.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Jun 4
2026
Gain visibility into DDoS attacks with flow logs in AWS Shield Advanced
Apr 8
2022
AWS Shield Advanced now supports Application Load Balancer for automatic application layer DDoS mitigation
Jul 27
2026
AWS Shield Advanced is embracing the AWS WAF Anti-DDoS managed rule group: What changes and how to prepare
Jun 12
2025
Introducing new application layer (L7) DDoS protections for AWS WAF and AWS Shield Advanced customers

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.