Back to news
cloud Priority 4/5 6/1/2026, 11:05:47 AM

AWS Shield Advanced Introduces Granular DDoS Attack Flow Logs for Improved Visibility

AWS Shield Advanced Introduces Granular DDoS Attack Flow Logs for Improved Visibility

AWS Shield Advanced has launched DDoS attack flow logs to provide deeper visibility into traffic targeting protected resources during active security events. These logs offer packet-level details that help security teams understand the nature of an attack and refine their mitigation strategies. The log data is integrated with Amazon S3 and Amazon CloudWatch Logs for centralized storage and analysis.

Related tools

Recommended tools for this topic

These picks prioritize high-intent tools relevant to this topic. Some links may include partner or affiliate tracking.

#aws#cloud#official

Comparison

AspectBefore / AlternativeAfter / This
Visibility depthHigh-level metrics and sample analysisPacket-level visibility during attacks
Log destinationAWS console dashboards onlyAmazon S3 and CloudWatch Logs
Post-event analysisManual reconstruction via samplingFull flow logs for forensic auditing

Action Checklist

  1. Enable Shield Advanced for relevant AWS resources Ensure the target resource is already protected by the Shield Advanced tier
  2. Configure an Amazon S3 bucket or CloudWatch log group Required for receiving the attack flow log data
  3. Set up IAM permissions for log delivery The Shield service role needs write access to your logging destination
  4. Enable DDoS attack flow logs in the Shield console This can be configured per resource under the protection settings

Source: AWS What's New

This page summarizes the original source. Check the source for full details.

Related