AWS Shield Advanced now offers attack flow logs that capture traffic metadata during DDoS events, eliminating the need to combine data from multiple sources after the fact. The logs can be published to Amazon S3, CloudWatch Logs, or Amazon Data Firehose, enabling organizations to analyze attack patterns, identify sources, and verify mitigation effectiveness. The article provides a comprehensive reference table of log fields and step-by-step configuration instructions for enabling logging on protected resources.