---
title: "Configure flow logs"
description: "Configure, filter, and aggregate Calico Enterprise flow logs. Add host endpoint, process path, and TCP socket statistics from in-cluster Elasticsearch."
product: "Calico Enterprise"
version: "3.23 (latest)"
section: "Observability"
canonical_url: "https://docs.tigera.io/calico-enterprise/latest/observability/elastic/flow/"
---

# Configure flow logs

## [📄️Flow log data types](https://docs.tigera.io/calico-enterprise/latest/observability/elastic/flow/datatypes.md)

[Reference of key/value fields that Calico Enterprise sends to Elasticsearch for flow logs, including endpoints, actions, byte counts, and policy verdicts.](https://docs.tigera.io/calico-enterprise/latest/observability/elastic/flow/datatypes.md)

## [📄️Filter flow logs](https://docs.tigera.io/calico-enterprise/latest/observability/elastic/flow/filtering.md)

[Filter Calico Enterprise flow logs through Fluentd to drop low-significance traffic and reduce in-cluster Elasticsearch volume and cost.](https://docs.tigera.io/calico-enterprise/latest/observability/elastic/flow/filtering.md)

## [📄️Configure flow log aggregation](https://docs.tigera.io/calico-enterprise/latest/observability/elastic/flow/aggregation.md)

[Tune Calico Enterprise flow log aggregation levels to balance Elasticsearch volume and cost against pod and IP visibility for allowed and denied traffic.](https://docs.tigera.io/calico-enterprise/latest/observability/elastic/flow/aggregation.md)

## [📄️Enable HostEndpoint reporting in flow logs](https://docs.tigera.io/calico-enterprise/latest/observability/elastic/flow/hep.md)

[Turn on host endpoint reporting in Calico Enterprise flow logs to gain visibility into traffic at HostEndpoint interfaces on Kubernetes nodes.](https://docs.tigera.io/calico-enterprise/latest/observability/elastic/flow/hep.md)

## [📄️Enabling TCP socket stats in flow logs](https://docs.tigera.io/calico-enterprise/latest/observability/elastic/flow/tcpstats.md)

[Add TCP socket statistics to Calico Enterprise flow logs with eBPF programs that capture round-trip time, retransmits, and other per-socket metrics.](https://docs.tigera.io/calico-enterprise/latest/observability/elastic/flow/tcpstats.md)

## [📄️Enable process-level information in flow logs](https://docs.tigera.io/calico-enterprise/latest/observability/elastic/flow/processpath.md)

[Add process executable paths and arguments to Calico Enterprise flow logs with eBPF instrumentation for process-level visibility into network activity.](https://docs.tigera.io/calico-enterprise/latest/observability/elastic/flow/processpath.md)
