For the complete documentation index, see llms.txt. This page is also available as Markdown.

Network Flow Queries

Prisma Cloud provides the userinput:[network from vpc.flow_record] network query that is based on networking logs, such as VPC flow logs, which you can use to detect when services, applications, or databases are exposed to the internet and fix risky configuration issues, or to search for assets that are receiving traffic and connections from suspicious IP addresses to prevent data exfiltration attempts before it is too late.

When you use the userinput:[network from vpc.flow_record where cloud.account=] RQL, the following are the list of resources for which you can visualize flow log information on Prisma Cloud:

Cloud Services

Resources that Support Flow Logs

AWS

  • AWS ElastiCache

  • AWS ELB

  • AWS Lambda

  • AWS NAT Gateway

  • AWS RDS

  • AWS Redshift

  • Container Management

  • Database

  • Email

  • FTP

  • FTP Client

  • HTTP

  • Kerberos Server

  • KVP Store

  • LDAP

  • Message Queue

  • Nagios Monitoring Server

  • Possible Cryptocurrency Miner

  • SSH

  • System Management

  • Telnet

  • VM Instance

  • Web Proxy

  • Web Server

Azure

  • Azure ELB

  • Container Management

  • Database

  • Email

  • FTP

  • Generic

  • HTTP

  • Kerberos Server

  • KVP Store

  • LDAP

  • Message Queue

  • Nagios Monitoring Server

  • SSH

  • System Management

  • Telnet

  • VM Instance

  • Web Proxy

  • Web Server

GCP

  • Google Kubernetes Engine (GKE) node

  • VM Instance

Network flow log queries are supported in AWS, Azure, and GCP cloud environments.

Last updated

Was this helpful?