AWS Shield Advanced adds DDoS attack flow logs
AWS Shield Advanced now offers DDoS attack flow logs, providing packet-level visibility into traffic during attacks. This feature aids forensic analysis and compliance by publishing detailed log data to S3, CloudWatch Logs, or Data Firehose. Available in all Shield Advanced regions, it requires protection with Shield Advanced and log delivery configuration.
- →DDoS attack flow logs for packet-level visibility
- →Log data export to S3, CloudWatch Logs, or Data Firehose
- →Prerequisites and availability for flow logs
Features (1) ›
- DDoS attack flow logs for packet-level visibility
AWS Shield Advanced now provides DDoS attack flow logs, offering packet-level insights into traffic during attacks. Log data includes source/destination IPs, ports, protocols, packet/byte counts, and source country, published at 5-minute intervals during active attacks.
Enhancements (1) ›
- Log data export to S3, CloudWatch Logs, or Data Firehose
DDoS attack flow logs can be automatically published to Amazon S3, Amazon CloudWatch Logs, or Amazon Data Firehose. This enables forensic analysis, compliance reporting, post-incident investigation, and threat intelligence gathering.
Notes (1) ›
- Prerequisites and availability for flow logs
To enable this feature, resources must be protected by Shield Advanced, and log delivery must be configured. DDoS attack flow logs are available in all AWS regions where AWS Shield Advanced is offered.
https://aws.amazon.com/about-aws/whats-new/2026/05/aws-shield-ddos/
Related releases
- Amazon MSK Express delivers Kafka data to Apache Iceberg streaming tables AWS What's New ·
- Amazon MSK Express delivers Kafka data to Amazon S3 AWS What's New ·
- Amazon OpenSearch Service Adds OpenSearch 3.7 Support AWS What's New ·
- AWS Parallel Computing Service adds node lifecycle actions AWS What's New ·
- Amazon S3 Tables add Variant type for Apache Iceberg V3 AWS What's New ·
- AWS Glue Data Quality Adds Distribution Statistics for Data Profiling AWS What's New ·