For the complete documentation index, see llms.txt. This page is also available as Markdown.

Configure Flow Logs

You can create flow logs using the DCD for your network interfaces and the public interfaces of the Managed Network Load Balancer (NLB) and Managed NAT Gateway. Flow logs can publish data to your buckets in the IONOS CLOUD Object Storage.

After you have created and configured your bucket in the IONOS CLOUD Object Storage, you can create flow logs for your network interfaces.

Prerequisites:

  • Only contract administrators, owners, and users with the Create Flow logs permission can create a flow log. Ensure that you have the necessary permission and sufficient memory available.

  • Make sure you have the corresponding privilege to enable IONOS CLOUD Object Storage. Only contract administrators and owners can enable Object Storage.

Activate flow logs

To activate flow logs, follow these steps:

1. In the DCD, go to Menu > Virtual Data Centers.

2. Open the required data center.

3. Go to the Server or Cubes element and select the Network tab. Open the properties of the Network Controller (NIC).

Accessing flow logs

4. Select the Flow Log drop-down list and fill in the fields. Provide an appropriate name for the flow log rule in the Name field. The name will also be the first part of the object name prefix.

Configure flow logs

3. Go to the Managed NAT Gateway or Managed Network Load Balancer element and select the Settings tab.

View of the Setting tab

4. Provide an appropriate name for the flow log rule in the Name field. The name will also be the first part of the objects’ name prefix.

View of the Flow Log drop-down list

5. To create flow logs for all traffic, choose a Direction from the drop-down list:

  • Ingress: Captures flow logs for incoming traffic.

  • Egress: Captures flow logs for outgoing traffic.

  • Bidirectional: Captures flow logs for both incoming and outgoing traffic.

6. Select an Action from the drop-down list to determine which traffic the system logs:

  • Rejected: Captures only traffic that the firewall blocks.

  • Accepted: Captures only traffic that the firewall allows.

  • Any: Captures all traffic.

7. Enter a valid existing IONOS CLOUD Object Storage bucket name in the Target Object Storage bucket field. This is an optional object name prefix where flow log records are written.

8. Select Add flow log to complete the configuration of the flow log. Once you provision your changes, it will be available .

Note:

  • Characters / (slash) and %2F are not supported as object prefix characters.

  • You cannot edit fields of a flow log rule after activating it.

  • There is a limit of one flow log created per NIC, Managed NAT Gateway, and Managed NLB.

Valid flow log rule

9. Select the Flow Log drop-down list and choose the name of the flow log rule for which you want to view the summary.

Flow log summary

10. (Optional) At this point, you may make further changes to your data center.

11. Once ready, select Provision changes. After provisioning is complete, the flow logs on the NIC are activated.

Note: Flow logs can be provisioned on both new and previously provisioned instances.

Last updated

Was this helpful?