What 3 Levels can you use flow logs at?
VPC
Subnet
Network Interface
Can you enable flow logs for peered VPC’s?
Only if the peered VPC is in your account
Can you tag a flow log?
No
Can you change the configuration of a flow log after you create it? i.e. change the IAM role
No
What traffic is never monitored?
instance traffic to the Amazon DNS Server
Windows instance for AWS license activation
to/from 169.254.169.254 for metadata
DHCP
to reserved IP address for default router