ingest-vpc-flow-logs-ocsf

Installation
SKILL.md

ingest-vpc-flow-logs-ocsf

Thin ingestion skill: raw AWS VPC Flow Log records in → canonical network-flow projection → OCSF 1.8 Network Activity JSONL or native enriched network-flow JSONL out. No detection logic, no AWS API calls, no side effects.

Wire contract

Reads VPC Flow Logs in the v5 space-delimited format that AWS delivers to CloudWatch Logs Insights, S3, or Kinesis Firehose. Each record is one line. The first line may be a header declaring the field order (CloudWatch delivery includes it; S3 delivery does not). When no header is present, the skill falls back to the canonical v5 default order:

version account-id interface-id srcaddr dstaddr srcport dstport protocol packets bytes start end action log-status

The skill also understands the v5 extended fields if they are declared in the header: vpc-id subnet-id instance-id tcp-flags type pkt-srcaddr pkt-dstaddr region az-id sublocation-type sublocation-id pkt-src-aws-service pkt-dst-aws-service flow-direction traffic-path.

By default it writes OCSF 1.8 Network Activity (class_uid: 4001, category_uid: 4). See ../OCSF_CONTRACT.md.

When --output-format native is selected, it emits the same flow in the repo's native enriched shape with stable event_uid, normalized source/destination, byte counters, protocol/direction, and AWS scope fields, but without the OCSF envelope.

Native output format

Installs
2
GitHub Stars
3
First Seen
Apr 20, 2026
ingest-vpc-flow-logs-ocsf — msaad00/cloud-ai-security-skills