---
title: VPC Flow Logs should be enabled for all VPC subnets
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > OOTB Rules > VPC Flow Logs should be enabled for all
  VPC subnets
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# VPC Flow Logs should be enabled for all VPC subnets
 
## Description{% #description %}

VPC Flow Logs should be enabled for applicable subnets to support network monitoring, forensics, and security analysis. Configure a five-second aggregation interval, 100% sampling, all metadata, and no exclusion filter. [Proxy-only subnets](https://docs.cloud.google.com/load-balancing/docs/proxy-only-subnets) and [Private Service Connect subnets](https://docs.cloud.google.com/vpc/docs/about-vpc-hosted-services) are excluded because they do not produce subnet flow records.

## Remediation{% #remediation %}

Follow [Configure VPC Flow Logs](https://cloud.google.com/vpc/docs/using-flow-logs#enabling_vpc_flow_logging) to enable logging with the required aggregation, sampling, metadata, and filter settings.
