aws AWS What's New ·

AWS Shield Advanced adds DDoS attack flow logs

securityawspreviewengineeraws-s3
feature

AWS Shield Advanced now offers DDoS attack flow logs, providing packet-level visibility into traffic during attacks. This feature aids forensic analysis and compliance by publishing detailed log data to S3, CloudWatch Logs, or Data Firehose. Available in all Shield Advanced regions, it requires protection with Shield Advanced and log delivery configuration.

  • DDoS attack flow logs for packet-level visibility
  • Log data export to S3, CloudWatch Logs, or Data Firehose
  • Prerequisites and availability for flow logs
Features (1)
  • DDoS attack flow logs for packet-level visibility

    AWS Shield Advanced now provides DDoS attack flow logs, offering packet-level insights into traffic during attacks. Log data includes source/destination IPs, ports, protocols, packet/byte counts, and source country, published at 5-minute intervals during active attacks.

Enhancements (1)
  • Log data export to S3, CloudWatch Logs, or Data Firehose

    DDoS attack flow logs can be automatically published to Amazon S3, Amazon CloudWatch Logs, or Amazon Data Firehose. This enables forensic analysis, compliance reporting, post-incident investigation, and threat intelligence gathering.

Notes (1)
  • Prerequisites and availability for flow logs

    To enable this feature, resources must be protected by Shield Advanced, and log delivery must be configured. DDoS attack flow logs are available in all AWS regions where AWS Shield Advanced is offered.

Read the original announcement →

https://aws.amazon.com/about-aws/whats-new/2026/05/aws-shield-ddos/

Related releases