Let's quickly go through some more important concepts related to flow logs:
- Currently, we cannot change a flow log configuration, such as changing the associated IAM role, once it's been created.
- Some of the IP traffic, including the ones listed here, are not monitored by flow logs:
- Traffic to the reserved IP addresses of the default VPC router.
- Dynamic Host Configuration Protocol (DHCP) traffic.
- Traffic set to 169.254.169.254 for querying instance metadata.
- Traffic while contacting Amazon DNS servers via instances. However, traffic to our own DNS server is logged.
- Windows license activation traffic.