The record of what actually happened, at the ENI, subnet, or VPC.
Safe to enable broadly — it's metadata, never packet payload.
# flow log entry — the field that matters most
srcaddr 10.0.1.15 dstaddr 10.0.2.40 dstport 5432 protocol 6 action REJECT # REJECT tells you definitively: SG or NACL blocked it. No guessing.
Destination matters: CloudWatch Logs for live alerting (costs more), S3 for cheap long-term Athena analysis, Kinesis Firehose for a third-party SIEM.