AWS Certified Advanced Networking – Specialty (ANS-C01)Network Management and OperationsHard

A large-scale application generates significant network traffic between EC2 instances. The network team wants to identify the top talkers and listeners within a VPC to optimize network performance and troubleshoot potential bottlenecks. The solution needs to process large volumes of flow data in near real-time and provide actionable insights. Which AWS service combination is best suited for this task?

  1. AVPC Flow Logs to Amazon Kinesis Data Firehose, then stream to Amazon OpenSearch Service for analysis and visualization.
  2. BAWS CloudTrail to Amazon S3, then analyze with AWS Glue.
  3. CVPC Flow Logs to Amazon S3, then analyze with Amazon Athena.
  4. DVPC Flow Logs to Amazon CloudWatch Logs, then analyze with CloudWatch Log Insights.
Show answer & explanation

Correct answer: A. VPC Flow Logs to Amazon Kinesis Data Firehose, then stream to Amazon OpenSearch Service for analysis and visualization.

To process large volumes of flow data in near real-time and gain actionable insights like top talkers/listeners, the combination of VPC Flow Logs directed to Kinesis Data Firehose, and then streamed to Amazon OpenSearch Service (formerly Elasticsearch Service) is ideal. Kinesis Firehose handles the high-volume ingestion, and OpenSearch Service provides powerful search, analytics, and visualization capabilities for real-time analysis of the flow data.

Why the other options are wrong

  • B. CloudTrail logs API calls, not network flow data, and AWS Glue is an ETL service, not a real-time analytics/visualization platform for network traffic.
  • C. S3 with Athena is good for ad-hoc querying of large datasets, but it's not near real-time and lacks built-in visualization for continuous monitoring of top talkers/listeners.
  • D. CloudWatch Logs with Log Insights is suitable for smaller to medium volumes of logs and provides good querying, but for very large-scale, near real-time, and advanced visualization of network flows, OpenSearch Service is more powerful.

Real-time VPC Flow Analysis

Using Kinesis Data Firehose to ingest VPC Flow Logs and then streaming them to Amazon OpenSearch Service for near real-time analysis and visualization of network traffic patterns.

  • Kinesis Firehose provides scalable, managed data ingestion.
  • OpenSearch Service offers powerful search, analytics, and visualization (Kibana/OpenSearch Dashboards).
  • Enables identification of top talkers, security threats, and performance bottlenecks in near real-time.

Memory trick: For 'fast flow' insights, 'firehose' to 'OpenSearch'.

More Network Management and Operations questions