VPC flow logs are configured to deliver records to CloudWatch Logs, but no logs are arriving. Which issue is most likely preventing the flow logs from being published to CloudWatch Logs?
Choose an answer
Tap an option to check your answer.
Correct answer: The IAM policy attached to the role used by the flow logs is missing the logs:CreateLogGroup permission..
Why this is the answer
The most likely reason flow logs aren't appearing in CloudWatch Logs is a missing logs:CreateLogGroup permission in the IAM policy attached to the role used by the flow logs. For VPC Flow Logs to deliver to CloudWatch Logs, the associated IAM role requires permissions to create the log group if it doesn't already exist, and to put log events into it. Without logs:CreateLogGroup, the initial log group creation fails, preventing any subsequent log delivery. logs:CreateExportTask is incorrect because this permission is for exporting logs from CloudWatch Logs to other destinations, not for the initial ingestion of flow logs. IPv6 addressing in the VPC is irrelevant to flow log delivery mechanics; flow logs support both IPv4 and IPv6 traffic. An active VPC peering connection also does not prevent flow logs from being published to CloudWatch Logs; flow logs capture traffic within the VPC regardless of peering.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed