You enabled VPC flow logs (default format) and are delivering them to CloudWatch Logs. Now you must include the tcp-flags field for deeper troubleshooting. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a new flow log that uses a custom format including tcp-flags, then delete the original flow log..
Why this is the answer
VPC Flow Logs, once created, cannot be modified to change their format or add/remove fields. To include the tcp-flags field, you must create a new flow log with a custom format that explicitly includes tcp-flags. After the new flow log is operational and logging data as desired, you can then delete the original flow log. Editing a CloudWatch Logs log group's filter only affects how logs are searched or displayed, not the data collected. CloudWatch Metrics are derived from log data but do not control the fields captured by VPC Flow Logs. Modifying an existing flow log is not an available option in AWS.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed