When:
I find this hard to remember, also it is very hard to convert numeric TCP flags to actual flags. Numeric protocol and other fields flowlogs provide are not super clear, if you don't work with flow logs on daily basis as well.
That's why I created flowlogs cli tool to make it easier to create and query flow logs with clear output - https://github.com/pete911/flowlogs