Skip to Main Content
Status Submitted
Workspace * IBM Cloud Ideas
Created by Guest
Created on Aug 7, 2026

Allow VPC Flow Logs to be delivered to a Cloud Object Storage instance in a different IBM Cloud account

Many enterprise customers deploy IBM Cloud using a Hub & Spoke architecture, where networking, security, logging, and monitoring services are centralized in a dedicated hub account, while workloads are deployed across multiple spoke accounts.

Currently, VPC Flow Logs can only be configured to deliver logs to a Cloud Object Storage (COS) instance located in the same IBM Cloud account as the VPC. This limitation prevents organizations from implementing a centralized logging architecture.

We would like IBM Cloud to support cross-account Cloud Object Storage destinations for VPC Flow Logs, allowing flow logs generated in spoke accounts to be written directly to a COS bucket located in a centralized logging account.

Access should be controlled using existing IBM Cloud IAM capabilities, such as Trusted Profiles, Service IDs, IAM authorization policies, or bucket-level permissions, ensuring secure cross-account access without compromising security.

Idea priority Medium
Needed By Not sure -- Just thought it was cool