---
title: "SD-WAN flow logs"
canonical: "https://docs.aryaka.com/space/KNOW/1610876/SD-WAN%20flow%20logs"
format: markdown
---
The SD-WAN Flow Logs page can be accessed from the Insights > Log Explorer page. It displays the list of flows for the selected site and time period. A  flow  is a series of communications between two network endpoints from the time a connection is established until it is terminated. If it is not already open, compete the following procedure to view the SD-WAN Flow Logs page: To open the SD-WAN Flow Logs page Log in to MyAryaka. The Home page appears. Click  Insights  >  Log Explorer  in the left navigation pane. The Log Explorer page appears. Click  Explore Logs  in the Flow Logs tile. The SD-WAN Flow Logs page appears.  Click the Reference Site drop-down menu and select the site you want to view flow logs for.  The components of the SD-WAN Flow Logs page are described in the following sections.  Filter The filter allows you to view flows that occurred during a defined time period or that meet selected criteria. You can select whether to use the Basic or Aryaka Query Language (AQL) filter to add filter criteria. The Time drop-down list allows you to select one of the following time periods to view flow logs for: Last 1 Hour Last 4 Hours Last 8 Hours Last 24 Hours Last 7 Days Last Day Last Week Custom Range After adding filter criteria, click  Apply  to activate the selected filter. To remove selected filters, click  Clear All . When you have created your filter, you can click  Save  to save the current filter criteria. You can then use the filter drop-down list to select a saved filter. Basic With the Basic filter, you can click the  Add  icon to filter the logs by specific criteria, for example, source IP, protocol, or destination port. When entering values, use the drop-down list to specify whether to search for logs that match the value (=), logs that do not match the value (!=), or, for some criteria, logs that have a partial match (~) for the value. When entering IP addresses, CIDR notation is supported. There are three types of available filter criteria: criteria that allow you to select multiple entires from a searchable drop-down list, criteria that allow you to enter multiple alphanumeric strings that are treated as OR conditionals (note that you must click  Update  to include entered values in the filter), and criteria that allow you to enter a range of values. AQL With the Aryaka Query Language (AQL) filter, you can manually enter the fields, conditions, and associated values you want to filter for. For example, to view only logs for traffic with a source zone of VPN0 and a destination port of 53, enter  SOURCE_ZONE = 'vpn0' AND DESTINATION_PORT = '53'  in the AQL field. The AQL filter allows you to use OR conditionals for different filter criteria, which is not possible with the Basic filter.   Statistics The Statistics pane displays a time series graph and drop-down panes that provide details on the displayed flow logs. If you want to hide the Statistics pane, click the Collapse icon.  The time series graph displays the total number of flows for the selected time period and filter criteria. The graph includes the following functionality: Hover over the graph to display the value of the statistic plotted on the graph at the corresponding time.  Click, drag, and release to select a smaller window of time to display. This custom time selection now applies to all graphs on MyAryaka. After you select a custom time period, it is retained until you click the Reset icon in the Filter pane. Click the  Expand  icon in the following drop-down panes to view statistics for the category: Clients Servers Destination Ports Protocols Managed Applications Source Networks Destination Networks Source Zones Destination Zones Peer Sites QoS Each drop-down pane displays the category’s top values for the selected flow logs. The following graphic shows the Clients drop-down pane expanded to display the top clients for the selected flow logs: You can use the values displayed in the drop-down panes to create a filter for your flow logs. For example, to view flow logs for your organization's top five clients, select the first five clients (shown in the following graphic), then click  Apply  in the filter pane to refresh the SD-WAN Flow Logs page with the logs that match your selection. Flow Logs table The Flow Logs table displays a row for each flow that occurred during the selected time period. The table displays the following columns by default: Event Time Discovered App Protocol Source IP Destination IP Destination Port Source Zone Destination Network Bytes Received Bytes Transmitted You can click the Gear icon to select which columns are displayed in the Flow Logs table. You can also click and drag the column names to reorder the columns as needed.  You can click the Download icon to download a CSV file of the flow logs to your local computer. The CSV file contains a column for each field of the flow logs table, regardless of which fields you have currently displayed.  You can hover over an individual cell in the table to display the Options icon. Click the  Options  icon, then click  Add to Filter  to create a filter with the corresponding criteria and value. Note that you must then click  Apply  to activate the filter.  Click a flow log to display the Log Preview pane, which provides additional event details. The Log Preview pane includes the following elements:  Share icon—Copies the MyAryaka URL for the selected flow log so that you can share it as needed. View Details—Displays the  SD-WAN flow Log details  page, which provides additional details about the event. Collapse icon—Hides the Log Preview pane.  Related topics View SD-WAN flow log details Monitor SD-WAN