bokamba / loganvil / AWS VPC Flow logs

$ loganvil generate aws-vpc-flow

Generate synthetic AWS VPC Flow logs

Generate realistic synthetic AWS VPC Flow logs (version 2, space-delimited) for pipeline testing, SIEM demos, and detection tuning — deterministic and 100% client-side. Each line carries the v2 fields — version, account-id, interface-id, srcaddr/dstaddr, srcport/dstport, protocol, packets, bytes, start/end, action, log-status — and a JSONL mode emits them under the real AWS field names. Round-trips through a VPC Flow parser. No real accounts or secrets.

Open the LogAnvil generator →

This sample, generated

The block below is 15 lines of AWS VPC Flow logs, produced by the real generator at seed 42 — deterministic, so this exact output regenerates anywhere. The live tool re-runs the identical engine on whatever source, seed, line count and anomalies you pick.

15lines
4.2stime span
0anomaly lines
42seed

no anomalies injected — raise a slider to seed detectable patterns

Generated AWS VPC Flow logs

Real on-the-wire AWS VPC Flow logs — no real users, IPs, or secrets. Copy it into a fixture, feed it to a parser, or seed a SIEM demo.

2 445566778899 eni-0123456789abcdef0 52.94.236.248 10.1.10.200 47634 53 17 4328 236180 1600000000000 1600000000000 ACCEPT OK
2 123456789012 eni-0abc12de34567890 13.107.42.14 192.168.1.50 50007 20 17 4187 25642 1600000000435 1600000000435 REJECT OK
2 123456789012 eni-0abc12de34567890 34.223.14.100 172.20.0.15 33533 23 1 2439 404519 1600000000643 1600000000643 ACCEPT OK
2 123456789012 eni-0f9e87dc65432100 13.107.42.14 10.1.10.200 50997 25 6 3694 429361 1600000000963 1600000000963 REJECT OK
2 123456789012 eni-0abc12de34567890 52.94.236.248 192.168.1.50 52335 8080 6 4719 215591 1600000001217 1600000001217 REJECT OK
2 123456789012 eni-0f9e87dc65432100 151.101.1.69 192.168.0.101 58164 21 1 4675 139154 1600000001454 1600000001454 REJECT OK
2 998877665544 eni-0abc12de34567890 93.184.216.34 172.20.0.15 58631 143 17 1685 298136 1600000001702 1600000001702 ACCEPT OK
2 445566778899 eni-0123456789abcdef0 52.94.236.248 192.168.100.254 57900 143 17 1480 50474 1600000002097 1600000002097 REJECT OK
2 998877665544 eni-0abc12de34567890 151.101.1.69 192.168.1.133 36437 8443 6 3548 349858 1600000002381 1600000002381 ACCEPT OK
2 445566778899 eni-0f9e87dc65432100 104.16.132.229 192.168.0.101 57806 80 1 1965 65731 1600000002691 1600000002691 REJECT OK
2 998877665544 eni-0f9e87dc65432100 185.199.108.153 192.168.10.7 38668 465 17 921 23775 1600000002990 1600000002990 REJECT OK
2 123456789012 eni-0f9e87dc65432100 8.8.8.8 10.1.10.200 60817 465 1 820 85450 1600000003379 1600000003379 REJECT OK
2 445566778899 eni-0f9e87dc65432100 52.94.236.248 172.16.4.9 42257 5432 6 2477 305451 1600000003657 1600000003657 REJECT OK
2 123456789012 eni-0abc12de34567890 140.82.113.4 192.168.1.50 39004 23 1 1572 62491 1600000004014 1600000004014 ACCEPT OK
2 123456789012 eni-0f9e87dc65432100 140.82.113.4 192.168.1.50 58533 3389 17 771 433821 1600000004225 1600000004225 REJECT OK

With an anomaly injected: Port scan

The same source, regenerated with a Port scan injected at 30% intensity. 7 line sare tagged and highlighted below — One source IP hitting many sequential destination ports — reconnaissance sweeping for open services. It is a documented, detectable pattern your SIEM rules should fire on — build the test data, then prove your detection works.

2 445566778899 eni-0123456789abcdef0 52.94.236.248 10.1.10.200 47634 53 17 4328 236180 1600000000000 1600000000000 ACCEPT OK
2 123456789012 eni-0abc12de34567890 13.107.42.14 192.168.1.50 50007 20 17 4187 25642 1600000000435 1600000000435 REJECT OK
2 123456789012 eni-0abc12de34567890 34.223.14.100 172.20.0.15 33533 23 1 2439 404519 1600000000643 1600000000643 ACCEPT OK
2 123456789012 eni-0f9e87dc65432100 13.107.42.14 10.1.10.200 50997 25 6 3694 429361 1600000000963 1600000000963 REJECT OK
2 123456789012 eni-0abc12de34567890 52.94.236.248 192.168.1.50 52335 8080 6 4719 215591 1600000001217 1600000001217 REJECT OK
2 123456789012 eni-0f9e87dc65432100 151.101.1.69 192.168.0.101 58164 21 1 4675 139154 1600000001454 1600000001454 REJECT OK
2 998877665544 eni-0abc12de34567890 93.184.216.34 172.20.0.15 58631 143 17 1685 298136 1600000001702 1600000001702 ACCEPT OK
2 445566778899 eni-0123456789abcdef0 52.94.236.248 192.168.100.254 57900 143 17 1480 50474 1600000002097 1600000002097 REJECT OK
162.243.128.12,203.0.113.230,94,78,REJECTPort scan
162.243.128.12,203.0.113.230,95,106,REJECTPort scan
162.243.128.12,203.0.113.230,96,50,REJECTPort scan
162.243.128.12,203.0.113.230,97,118,REJECTPort scan
162.243.128.12,203.0.113.230,98,54,REJECTPort scan
162.243.128.12,203.0.113.230,99,97,REJECTPort scan
162.243.128.12,203.0.113.230,100,96,REJECTPort scan

FAQ

Are these real VPC Flow logs?
No — the output is synthetic. It reproduces the AWS VPC Flow v2 column layout exactly (and the AWS field names in JSONL mode), but every account, interface, address and byte count is fabricated. Safe for fixtures, demos and parser tests.
Can I inject anomalies?
Yes. A port scan fits flow logs perfectly: the slider appends a sweep of one source across many sequential destination ports with tiny byte counts, in faithful CSV grammar. Injected lines are highlighted and badged so you can verify your recon detection fires.
Is the output deterministic?
Yes — fully seeded. The same seed and config always produce byte-identical VPC Flow lines, so a committed seed regenerates the identical log on any machine or in CI.

Generate other log sources

Open the LogAnvil generator to tune the seed, line count, EPS, format and anomaly sliders — or build a parser with LogForge for a log you already have.

Generate your own AWS VPC Flow logs

Pick the seed, line count and EPS, inject the anomalies your rules should catch, and copy or download the result. Free, no account, nothing uploaded — generation runs entirely in your browser.

Open the LogAnvil generator →