This how-to guide introduces AWS Shield Advanced attack flow logs, which capture metadata during DDoS events and integrate with existing monitoring tools. The post details flow log fields including source/destination IPs, protocols, packet counts, and actions taken, and provides step-by-step configuration instructions using AWS CLI for reconstructing traffic patterns and identifying attack origins.