Simple Log Service lets you use the Flowlog center to visually analyze VPC flow logs. This topic describes how to set up the Flowlog center.
Prerequisites
You have activated Simple Log Service on the Simple Log Service product page.
You have created a project and a Logstore to manage and store captured traffic. For more information, see Manage projects and Create a basic Logstore.
You have configured an index for the associated Logstore. For more information, see Create an index.
You have created a flow log. For more information, see Create and manage a flow log.
Analyze flow logs through the Flowlog Log Center
By analyzing flow logs, you can check access control rules, monitor network traffic, and troubleshoot network faults.
Log on to theLog Service console.
In log applicationregion, clickView more log applications, and then in log application dialog box, clickFlowlog Log Center.
In Flowlog Managementpage, clickAdd.
In Create an instance panel, configure the following parameters, and then clickOK.
parameter
Description
instanceID
logservice provides by defaultinstanceID. You can also customize the instanceID.
instance name
Configure the instance name.
Project
Select the Project that you have created. The Project must be the same as the Project configured in the flowlog that you createdct remain consistent.
Logstore
Select the Logstore that you have created. The Logstore must be the same as the Logstore configured in the flowlog that you createdstore remain consistent.
After the instance is created successfully, you can view it in Flowlog Log Center listview the createdinstance.

In instanceID column, click the instanceID.
In FlowlogDetailspage, You canview andanalysisflowlog information.

monitoringcenterprovides the following dashboards and custom queriesfeature:
Overview: Displaysflowlog overall information.
policy statistics: DisplaysAccepttrends, Rejecttrends, Acceptcount statistics (consisting of 5-tuples), Rejectcount statistics (consisting of 5-tuples) and other information.A 5-tuple is a set consisting of source network segment, source port, protocol type, destination network segment, and destination port.
Accept: Security groups and networkACLthe traffic allowed to be logged.
Reject: Security groups and networkACLtraffic denied to be logged.
ENIflow volume: Displays the incoming and outgoing traffic of the ENIflow volume information.
ECS-flow volume: DisplaysECS instance traffic.
custom query: You canby yourselfquery andanalysisVPCflowlog.For more information, seequery andanalysislog.
In FlowlogDetailspage, clicknetwork segmentSettings, and then in network segmentSettings tab, and turn on theEnable“Inter-domain analysis” switch.
After the inter-domain analysis feature is enabled, the system automatically creates a data processing task to generate VPCflowlog, Used foranalysistraffic between different network segments.data processingfeaturewill incur certain fees. You canSelect whether toEnableInter-domain analysisfeature.For more information about data processingfeatureFor specific billing details, seebased on usagefeaturebilling mode billing items.
logservice has preset multiple network segments, as shown in the following figure.When you need toanalysistraffic between different network segments, you only need to enable it with one clickEnableInter-domain analysisfeature.If the preset network segments do not meet your requirements, You cancustom addnetwork segment.
Inter-domain analysisprovides the following dashboards and custom queriesfeature:
inter-domain traffic: Displaystraffic between different network segments.
ECSto segment traffic: DisplaysECS instance traffic to the destination network segment.
threat intelligence: DisplayssourceIPaddress and destinationIP address threat intelligence information.
custom query: You canby yourselfquery andanalysis with network segment informationVPCflowlog.For more information, seequery andanalysislog.
What to do next
View dashboards such as Policy Statistics, ENI Traffic, and Inter-ECS Traffic.
View dashboards such as Inter-Domain Traffic, ECS-to-Range Traffic, and Threat Intelligence.
Perform custom queries and analysis. For more information, see Get started with log query and analysis.