Prerequisites
- AgentGuard setup is complete: your AWS account shows Status = UP and your workloads appear under Cloud Assets.
- Permission to enable VPC flow logs in your AWS account.
AgentGuard phase one supports AWS only. Support for additional clouds is planned for the future.
Step 1: Turn On VPC Flow Logs
When you use the deeper visibility and enforcement approach, you do not need to enable VPC flow logs. The gateway provides the traffic signal directly. See
Get Deep Visibility and Enforcement With a Gateway.
1
Enable flow logs to an S3 bucket
In the AWS Console, enable VPC Flow Logs for your VPC and send them
to an S3 bucket.
2
Include the required fields
Configure the flow log format to include the following fields:
3
Confirm that the role can read the logs
Confirm that the onboarded role has the
ec2:DescribeFlowLogs and
s3:GetObject permissions so that AgentGuard can read the bucket.Flow log data takes 15–20 minutes to arrive. You can monitor the status in the AWS Console.
Step 2: Discover Your AI Workloads
AgentGuard lists every AI workload that it discovers and labels each one by the destination it communicates with (the AI vendor).1
Open the AI Workloads inventory
From the Aviatrix Cloud Console, navigate to Security > AgentGuard > AI Workloads.
2
Display all workloads
Set the filter to All Workloads to display the totals and the summary
charts.
3
Review the vendor for each workload
Locate your AI workloads in the list. Each workload shows an AI Vendor,
such as an LLM client or an agent-to-agent client. An internally hosted
workload is shown as Self-Hosted, and an externally hosted workload that
does not match the vendor list is shown as UNKNOWN.
4
Open a workload's details
Select a workload to open its details, and confirm that the fields are
populated: IP addresses, cluster, region, type, and vendor.
Troubleshooting
The AI Workloads list is empty
The AI Workloads list is empty
Confirm that the account is UP and that the VPC and cluster are
onboarded. If the list is still empty, confirm that the role has the
eks:DescribeCluster permission.A vendor shows UNKNOWN
A vendor shows UNKNOWN
Confirm that DNS logging is enabled and that the workload calls a known
provider. Externally hosted servers show UNKNOWN unless you label them.
The risk level is N/A
The risk level is N/A
Confirm that VPC flow logs are enabled and that the role can read the S3
bucket, then wait approximately 20 minutes. The tooltip identifies what is
missing.
Next Steps
- To add full-detail AI traffic analysis and enforcement, continue to Get Deep Visibility and Enforcement With a Gateway.