Network Flow Queries
Last updated
Was this helpful?
Prisma Cloud provides the userinput:[network from vpc.flow_record] network query that is based on networking logs, such as VPC flow logs, which you can use to detect when services, applications, or databases are exposed to the internet and fix risky configuration issues, or to search for assets that are receiving traffic and connections from suspicious IP addresses to prevent data exfiltration attempts before it is too late.
When you use the userinput:[network from vpc.flow_record where cloud.account=] RQL, the following are the list of resources for which you can visualize flow log information on Prisma Cloud:
Cloud Services
Resources that Support Flow Logs
AWS
AWS ElastiCache
AWS ELB
AWS Lambda
AWS NAT Gateway
AWS RDS
AWS Redshift
Container Management
Database
FTP
FTP Client
HTTP
Kerberos Server
KVP Store
LDAP
Message Queue
Nagios Monitoring Server
Possible Cryptocurrency Miner
SSH
System Management
Telnet
VM Instance
Web Proxy
Web Server
Azure
Azure ELB
Container Management
Database
FTP
Generic
HTTP
Kerberos Server
KVP Store
LDAP
Message Queue
Nagios Monitoring Server
SSH
System Management
Telnet
VM Instance
Web Proxy
Web Server
GCP
Google Kubernetes Engine (GKE) node
VM Instance
Network flow log queries are supported in AWS, Azure, and GCP cloud environments.
Last updated
Was this helpful?
Was this helpful?

