> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aviatrix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get Basic Visibility Without a Gateway

> Discover every AI workload, review its classification by vendor, and read a risk level for each — with no changes to your network.

This guide covers turning on VPC flow logs to discover your AI workloads.

After you complete
[setup](/docs/cloud/security/agentguard/getting-started/agentguard-setup),
AgentGuard presents an inventory of your AI workloads and a risk level
for each one, when VPC flow logs are enabled. This basic visibility
requires no changes to your network.

## Prerequisites

* [AgentGuard setup](/docs/cloud/security/agentguard/getting-started/agentguard-setup)
  is complete: your AWS account shows **Status = UP** and your workloads appear
  under **Cloud Assets**.
* Permission to enable VPC flow logs in your AWS account.

<Note>
  AgentGuard phase one supports AWS only. Support for additional clouds is planned for the future.
</Note>

## Step 1: Turn On VPC Flow Logs

<Note>
  When you use the deeper visibility and enforcement approach, you do not need to enable VPC flow logs. The gateway provides the traffic signal directly. See
  [Get Deep Visibility and Enforcement With a Gateway](/docs/cloud/security/agentguard/getting-started/agentguard-with-gateway).
</Note>

<Steps>
  <Step title="Enable flow logs to an S3 bucket">
    In the **AWS Console**, enable **VPC Flow Logs** for your VPC and send them
    to an **S3 bucket**.
  </Step>

  <Step title="Include the required fields">
    Configure the flow log format to include the following fields:

    ```text theme={null}
    ${version} ${account-id} ${interface-id} ${srcaddr} ${dstaddr}
    ${srcport} ${dstport} ${protocol} ${packets} ${bytes} ${start} ${end}
    ${action} ${log-status} ${vpc-id} ${subnet-id} ${instance-id}
    ${tcp-flags} ${type} ${pkt-srcaddr} ${pkt-dstaddr} ${resource-id}
    ```
  </Step>

  <Step title="Confirm that the role can read the logs">
    Confirm that the onboarded role has the `ec2:DescribeFlowLogs` and
    `s3:GetObject` permissions so that AgentGuard can read the bucket.
  </Step>
</Steps>

<Note>
  Flow log data takes 15–20 minutes to arrive. You can monitor the status in the **AWS Console**.
</Note>

## Step 2: Discover Your AI Workloads

AgentGuard lists every AI workload that it discovers and labels each one by the
destination it communicates with (the AI vendor).

<Steps>
  <Step title="Open the AI Workloads inventory">
    From the Aviatrix Cloud Console, navigate to **Security > AgentGuard > AI Workloads**.
  </Step>

  <Step title="Display all workloads">
    Set the filter to **All Workloads** to display the totals and the summary
    charts.
  </Step>

  <Step title="Review the vendor for each workload">
    Locate your AI workloads in the list. Each workload shows an **AI Vendor**,
    such as an LLM client or an agent-to-agent client. An internally hosted
    workload is shown as **Self-Hosted**, and an externally hosted workload that
    does not match the vendor list is shown as **UNKNOWN**.
  </Step>

  <Step title="Open a workload's details">
    Select a workload to open its details, and confirm that the fields are
    populated: IP addresses, cluster, region, type, and vendor.
  </Step>
</Steps>

<Tip>
  Both managed services, such as AWS Bedrock, and self-managed pods appear, each
  with a type and vendor. Newly deployed workloads appear within approximately
  10–15 minutes. Vendor names are derived from DNS, so self-hosted servers, such
  as Ollama, can appear as **Self-Hosted** or **UNKNOWN**, depending on where
  they are hosted.
</Tip>

## Troubleshooting

<AccordionGroup>
  <Accordion title="The AI Workloads list is empty">
    Confirm that the account is **UP** and that the VPC and cluster are
    onboarded. If the list is still empty, confirm that the role has the
    `eks:DescribeCluster` permission.
  </Accordion>

  <Accordion title="A vendor shows UNKNOWN">
    Confirm that DNS logging is enabled and that the workload calls a known
    provider. Externally hosted servers show **UNKNOWN** unless you label them.
  </Accordion>

  <Accordion title="The risk level is N/A">
    Confirm that VPC flow logs are enabled and that the role can read the S3
    bucket, then wait approximately 20 minutes. The tooltip identifies what is
    missing.
  </Accordion>
</AccordionGroup>

## Next Steps

* To add full-detail AI traffic analysis and enforcement, continue to
  [Get Deep Visibility and Enforcement With a Gateway](/docs/cloud/security/agentguard/getting-started/agentguard-with-gateway).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.