Many enterprise customers deploy IBM Cloud using a Hub & Spoke architecture, where networking, security, logging, and monitoring services are centralized in a dedicated hub account, while workloads are deployed across multiple spoke accounts.
Currently, VPC Flow Logs can only be configured to deliver logs to a Cloud Object Storage (COS) instance located in the same IBM Cloud account as the VPC. This limitation prevents organizations from implementing a centralized logging architecture.
We would like IBM Cloud to support cross-account Cloud Object Storage destinations for VPC Flow Logs, allowing flow logs generated in spoke accounts to be written directly to a COS bucket located in a centralized logging account.
Access should be controlled using existing IBM Cloud IAM capabilities, such as Trusted Profiles, Service IDs, IAM authorization policies, or bucket-level permissions, ensuring secure cross-account access without compromising security.
| Idea priority | Medium |
| Needed By | Not sure -- Just thought it was cool |
By clicking the "Post Comment" or "Submit Idea" button, you are agreeing to the IBM Ideas Portal Terms of Use.
Do not place IBM confidential, company confidential, or personal information into any field.