More Info:

Ensures VPC flow logs are enabled for traffic logging.

Risk Level

Low

Address

Security

Compliance Standards

CISGCP, CBP, HIPAA, ISO27001, NIST

Triage and Remediation

Remediation

To remediate the misconfiguration “VPC Flow Logs Should Be Enabled” for GCP using GCP console, follow these steps:

  1. Open the Google Cloud Console and navigate to the VPC network that you want to enable flow logs for.

  2. Click on the “VPC network details” button.

  3. In the “VPC network details” page, click on the “Logs” tab.

  4. Click on the “Configure logs” button.

  5. In the “Configure logs” page, select the “VPC flow logs” option.

  6. Choose the “Create a new sink” option.

  7. Enter a name for the new sink and select the destination for the logs.

  8. Click on the “Create sink” button.

  9. Once the sink is created, click on the “Save” button.

  10. The VPC flow logs are now enabled for the selected VPC network.

Note: It is recommended to create a separate project for storing logs to ensure proper access control and security.

Additional Reading: