Learn how traffic visibility helps you understand cloud traffic and threats, and find the setup procedure for your AWS, Azure, or Google Cloud Platform account.
To understand traffic flows within your cloud account, enabling traffic visibility collects these types of logs:
-
VPC or VNet flow logs
-
DNS logs
-
Route53 query logging
Flow and DNS query logs help Multicloud Defense to understand traffic flow, correlate data with threat intelligence feeds, and gain insights into existing threats protected by Multicloud Defense.
Enabling traffic visibility varies by cloud account type. Identify the characteristics of your cloud account, including the region, VPC/VNet for monitoring, network security groups, and a cloud storage account for logs.
Multicloud Defense does not support traffic visibility for OCI at this time. Enable asset discovery as an alternative action for this procedure: which means Multicloud Defense identifies and collects metadata for assets from an external environment and the resulting data collected creates an inventory that can be used to assist migration. For more information, refer to Enable Asset Discovery and Inventory.