Create Traffic Mirror Session
ec2_create_traffic_mirror_session | R Documentation |
Creates a Traffic Mirror session¶
Description¶
Creates a Traffic Mirror session.
A Traffic Mirror session actively copies packets from a Traffic Mirror source to a Traffic Mirror target. Create a filter, and then assign it to the session to define a subset of the traffic to mirror, for example all TCP traffic.
The Traffic Mirror source and the Traffic Mirror target (monitoring appliances) can be in the same VPC, or in a different VPC connected via VPC peering or a transit gateway.
By default, no traffic is mirrored. Use create_traffic_mirror_filter
to create filter rules that specify the traffic to mirror.
Usage¶
ec2_create_traffic_mirror_session(NetworkInterfaceId,
TrafficMirrorTargetId, TrafficMirrorFilterId, PacketLength,
SessionNumber, VirtualNetworkId, Description, TagSpecifications, DryRun,
ClientToken)
Arguments¶
NetworkInterfaceId |
[required] The ID of the source network interface. |
TrafficMirrorTargetId |
[required] The ID of the Traffic Mirror target. |
TrafficMirrorFilterId |
[required] The ID of the Traffic Mirror filter. |
PacketLength |
The number of bytes in each packet to mirror. These are bytes after the VXLAN header. Do not specify this parameter when you want to mirror the entire packet. To mirror a subset of the packet, set this to the length (in bytes) that you want to mirror. For example, if you set this value to 100, then the first 100 bytes that meet the filter criteria are copied to the target. If you do not want to mirror the entire packet, use the
For sessions with Network Load Balancer (NLB) Traffic Mirror targets
the default |
SessionNumber |
[required] The session number determines the order in which sessions are evaluated when an interface is used by multiple sessions. The first session with a matching filter is the one that mirrors the packets. Valid values are 1-32766. |
VirtualNetworkId |
The VXLAN ID for the Traffic Mirror session. For more information
about the VXLAN protocol, see RFC 7348. If
you do not specify a |
Description |
The description of the Traffic Mirror session. |
TagSpecifications |
The tags to assign to a Traffic Mirror session. |
DryRun |
Checks whether you have the required permissions for the action,
without actually making the request, and provides an error response. If
you have the required permissions, the error response is
|
ClientToken |
Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see How to ensure idempotency. |
Value¶
A list with the following syntax:
list(
TrafficMirrorSession = list(
TrafficMirrorSessionId = "string",
TrafficMirrorTargetId = "string",
TrafficMirrorFilterId = "string",
NetworkInterfaceId = "string",
OwnerId = "string",
PacketLength = 123,
SessionNumber = 123,
VirtualNetworkId = 123,
Description = "string",
Tags = list(
list(
Key = "string",
Value = "string"
)
)
),
ClientToken = "string"
)
Request syntax¶
svc$create_traffic_mirror_session(
NetworkInterfaceId = "string",
TrafficMirrorTargetId = "string",
TrafficMirrorFilterId = "string",
PacketLength = 123,
SessionNumber = 123,
VirtualNetworkId = 123,
Description = "string",
TagSpecifications = list(
list(
ResourceType = "capacity-reservation"|"client-vpn-endpoint"|"customer-gateway"|"carrier-gateway"|"coip-pool"|"declarative-policies-report"|"dedicated-host"|"dhcp-options"|"egress-only-internet-gateway"|"elastic-ip"|"elastic-gpu"|"export-image-task"|"export-instance-task"|"fleet"|"fpga-image"|"host-reservation"|"image"|"import-image-task"|"import-snapshot-task"|"instance"|"instance-event-window"|"internet-gateway"|"ipam"|"ipam-pool"|"ipam-scope"|"ipv4pool-ec2"|"ipv6pool-ec2"|"key-pair"|"launch-template"|"local-gateway"|"local-gateway-route-table"|"local-gateway-virtual-interface"|"local-gateway-virtual-interface-group"|"local-gateway-route-table-vpc-association"|"local-gateway-route-table-virtual-interface-group-association"|"natgateway"|"network-acl"|"network-interface"|"network-insights-analysis"|"network-insights-path"|"network-insights-access-scope"|"network-insights-access-scope-analysis"|"placement-group"|"prefix-list"|"replace-root-volume-task"|"reserved-instances"|"route-table"|"security-group"|"security-group-rule"|"snapshot"|"spot-fleet-request"|"spot-instances-request"|"subnet"|"subnet-cidr-reservation"|"traffic-mirror-filter"|"traffic-mirror-session"|"traffic-mirror-target"|"transit-gateway"|"transit-gateway-attachment"|"transit-gateway-connect-peer"|"transit-gateway-multicast-domain"|"transit-gateway-policy-table"|"transit-gateway-route-table"|"transit-gateway-route-table-announcement"|"volume"|"vpc"|"vpc-endpoint"|"vpc-endpoint-connection"|"vpc-endpoint-service"|"vpc-endpoint-service-permission"|"vpc-peering-connection"|"vpn-connection"|"vpn-gateway"|"vpc-flow-log"|"capacity-reservation-fleet"|"traffic-mirror-filter-rule"|"vpc-endpoint-connection-device-type"|"verified-access-instance"|"verified-access-group"|"verified-access-endpoint"|"verified-access-policy"|"verified-access-trust-provider"|"vpn-connection-device-type"|"vpc-block-public-access-exclusion"|"ipam-resource-discovery"|"ipam-resource-discovery-association"|"instance-connect-endpoint"|"verified-access-endpoint-target"|"ipam-external-resource-verification-token",
Tags = list(
list(
Key = "string",
Value = "string"
)
)
)
),
DryRun = TRUE|FALSE,
ClientToken = "string"
)