VPC Flow Logs allows you to capture IP traffic information that flows between your Network Interfaces of your resources within your VPC.
This is useful to help resolve incidents with network communication and for security purposes like spotting traffic from or to destination that are not allowed.
Logs are saved to CloudWatch or S3.
Flow Logs can be set up against:
a specific NI on one specific instance
a subnet with the VPC
the VPC itself
DHCP traffic and traffic that goes to Route53 is excluded from monitoring.