<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Source IP on Cloudkaramchari</title><link>https://www.cloudkaramchari.com/tags/source-ip/</link><description>Recent content in Source IP on Cloudkaramchari</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>cloudkaramchari</copyright><lastBuildDate>Tue, 08 Sep 2026 11:00:00 +0530</lastBuildDate><atom:link href="https://www.cloudkaramchari.com/tags/source-ip/index.xml" rel="self" type="application/rss+xml"/><item><title>Find Source IP Addresses Connecting to AWS Transfer Family SFTP with CloudWatch Logs Insights</title><link>https://www.cloudkaramchari.com/blog/find-source-ip-addresses-aws-transfer-family-sftp-cloudwatch-logs-insights/</link><pubDate>Tue, 08 Sep 2026 11:00:00 +0530</pubDate><guid>https://www.cloudkaramchari.com/blog/find-source-ip-addresses-aws-transfer-family-sftp-cloudwatch-logs-insights/</guid><description>
&lt;h1 id="find-source-ip-addresses-connecting-to-aws-transfer-family-sftp-with-cloudwatch-logs-insights">Find Source IP Addresses Connecting to AWS Transfer Family SFTP with CloudWatch Logs Insights&lt;/h1>
&lt;p>If your AWS Transfer Family SFTP server has CloudWatch logging turned on, every connection, login attempt, and file operation is already sitting in a log group — you just need the right query to pull the source IPs out of it. This comes up in three situations: someone reports failed logins and you need to know where they're coming from, you're building an IP allowlist and need a baseline of who's actually connecting today, or an audit asks &amp;quot;who accessed this SFTP server and from where&amp;quot; and the honest answer is &amp;quot;let me go check.&amp;quot;&lt;/p></description></item></channel></rss>