Skip to content

AWS VPC Flow Logs

You can integrate AWS VPC Flow Logs with Sophos XDR so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

AWS VPC Flow Logs product overview

AWS VPC Flow Logs is an Amazon VPC feature that captures information about the IP traffic going to and from network interfaces in your VPC, recording each flow's source and destination IP address and port, protocol, packet and byte counts, and whether the traffic was accepted or rejected.

What we ingest

Sophos XDR collects AWS VPC Flow Logs from an Amazon S3 bucket: you deploy a CloudFormation template that provisions a Lambda function, which forwards flow log files to Sophos XDR as they are delivered to the bucket. Logs must use the default VPC Flow Logs format. The following log categories are collected:

  • Network flows 1: VPC network-interface IP traffic flow records.

Event and data types

We ingest the following event and data types from AWS VPC Flow Logs:

  • Network flows 1: VPC network-interface IP traffic flow records (5-tuple), including source and destination IP and port, protocol, packet and byte counts, and the accept or reject action. Normalized to netflow telemetry.

Data provided by this integration

Data provided by AWS VPC Flow Logs gets normalized to the following schemas:

  • netflow 1

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation


  1. Netflow telemetry is only available to NG-SIEM subscribers.