--- layout: "aws" page_title: "AWS: aws_flow_log" sidebar_current: "docs-aws-resource-flow-log" description: |- Provides a VPC/Subnet/ENI Flow Log --- # aws\_flow\_log Provides a VPC/Subnet/ENI Flow Log to capture IP traffic for a specific network interface, subnet, or VPC. Logs are sent to a CloudWatch Log Group. ``` resource "aws_flow_log" "test_flow_log" { log_group_name = "${aws_cloudwatch_log_group.test_log_group.name}" iam_role_arn = "${aws_iam_role.test_role.arn}" vpc_id = "${aws_vpc.default.id}" traffic_type = "ALL" } resource "aws_cloudwatch_log_group" "test_log_group" { name = "test_log_group" } resource "aws_iam_role" "test_role" { name = "test_role" assume_role_policy = <