Skip to main content
This guide covers turning on VPC flow logs to discover your AI workloads. After you complete setup, AgentGuard presents an inventory of your AI workloads and a risk level for each one, when VPC flow logs are enabled. This basic visibility requires no changes to your network.

Prerequisites

  • AgentGuard setup is complete: your AWS account shows Status = UP and your workloads appear under Cloud Assets.
  • Permission to enable VPC flow logs in your AWS account.
AgentGuard phase one supports AWS only. Support for additional clouds is planned for the future.

Step 1: Turn On VPC Flow Logs

When you use the deeper visibility and enforcement approach, you do not need to enable VPC flow logs. The gateway provides the traffic signal directly. See Get Deep Visibility and Enforcement With a Gateway.
1

Enable flow logs to an S3 bucket

In the AWS Console, enable VPC Flow Logs for your VPC and send them to an S3 bucket.
2

Include the required fields

Configure the flow log format to include the following fields:
3

Confirm that the role can read the logs

Confirm that the onboarded role has the ec2:DescribeFlowLogs and s3:GetObject permissions so that AgentGuard can read the bucket.
Flow log data takes 15–20 minutes to arrive. You can monitor the status in the AWS Console.

Step 2: Discover Your AI Workloads

AgentGuard lists every AI workload that it discovers and labels each one by the destination it communicates with (the AI vendor).
1

Open the AI Workloads inventory

From the Aviatrix Cloud Console, navigate to Security > AgentGuard > AI Workloads.
2

Display all workloads

Set the filter to All Workloads to display the totals and the summary charts.
3

Review the vendor for each workload

Locate your AI workloads in the list. Each workload shows an AI Vendor, such as an LLM client or an agent-to-agent client. An internally hosted workload is shown as Self-Hosted, and an externally hosted workload that does not match the vendor list is shown as UNKNOWN.
4

Open a workload's details

Select a workload to open its details, and confirm that the fields are populated: IP addresses, cluster, region, type, and vendor.
Both managed services, such as AWS Bedrock, and self-managed pods appear, each with a type and vendor. Newly deployed workloads appear within approximately 10–15 minutes. Vendor names are derived from DNS, so self-hosted servers, such as Ollama, can appear as Self-Hosted or UNKNOWN, depending on where they are hosted.

Troubleshooting

Confirm that the account is UP and that the VPC and cluster are onboarded. If the list is still empty, confirm that the role has the eks:DescribeCluster permission.
Confirm that DNS logging is enabled and that the workload calls a known provider. Externally hosted servers show UNKNOWN unless you label them.
Confirm that VPC flow logs are enabled and that the role can read the S3 bucket, then wait approximately 20 minutes. The tooltip identifies what is missing.

Next Steps