You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
### Supported metrics for microsoft.network/vpngateways
27
+
| Metric | Description|
28
+
| --- | --- |
29
+
|**Virtual Hub Data Processed**| Data on how much traffic traverses the virtual hub router in a given time period. Only the following flows use the virtual hub router: VNet to VNet (same hub and interhub) and VPN/ExpressRoute branch to VNet (interhub). If a virtual hub is secured with routing intent, then these flows traverse the firewall instead of the hub router. |
30
+
| **Routing Infrastructure Units** | The virtual hub's routing infrastructure units (RIU). The virtual hub's RIU determines how much bandwidth the virtual hub router can process for flows traversing the virtual hub router. The hub's RIU also determines how many VMs in spoke VNets the virtual hub router can support. For more details on routing infrastructure units, see [Virtual Hub Capacity](hub-settings.md#capacity).
31
+
|**Spoke VM Utilization**| The approximate number of deployed spoke VMs as a percentage of the total number of spoke VMs that the hub's routing infrastructure units can support. For example, if the hub's RIU is set to 2 (which supports 2000 spoke VMs), and 1000 VMs are deployed across spoke VNets, then this metric's value will be approximately 50%. |
32
+
33
+
34
+
### <aname="s2s-metrics"></a>Supported metrics for microsoft.network/vpngateways
28
35
29
36
The following table lists the metrics available for the microsoft.network/vpngateways resource type.
### Supported metrics for microsoft.network/p2svpngateways
42
+
43
+
#### Tunnel Packet Drop metrics
44
+
45
+
| Metric | Description|
46
+
| --- | --- |
47
+
|**Tunnel Egress Packet Drop Count**| Count of Outgoing packets dropped by tunnel.|
48
+
|**Tunnel Ingress Packet Drop Count**| Count of Incoming packets dropped by tunnel.|
49
+
|**Tunnel NAT Packet Drops**| Number of NATed packets dropped on a tunnel by drop type and NAT rule.|
50
+
|**Tunnel Egress TS Mismatch Packet Drop**| Outgoing packet drop count from traffic selector mismatch of a tunnel.|
51
+
|**Tunnel Ingress TS Mismatch Packet Drop**| Incoming packet drop count from traffic selector mismatch of a tunnel.|
52
+
53
+
#### IPSec metrics
54
+
55
+
| Metric | Description|
56
+
| --- | --- |
57
+
|**Tunnel MMSA Count**| Number of MMSAs getting created or deleted.|
58
+
|**Tunnel QMSA Count**| Number of IPSEC QMSAs getting created or deleted.|
59
+
60
+
#### Routing metrics
61
+
62
+
| Metric | Description|
63
+
| --- | --- |
64
+
|**BGP Peer Status**| BGP connectivity status per peer and per instance.|
65
+
|**BGP Routes Advertised**| Number of routes advertised per peer and per instance.|
66
+
|**BGP Routes Learned**| Number of routes learned per peer and per instance.|
67
+
|**VNET Address Prefix Count**| Number of VNet address prefixes that are used/advertised by the gateway.|
68
+
69
+
You can review per peer and instance metrics by selecting **Apply splitting** and choosing the preferred value.
70
+
71
+
#### Traffic Flow metrics
72
+
73
+
| Metric | Description|
74
+
| --- | --- |
75
+
|**Gateway Bandwidth**| Average site-to-site aggregate bandwidth of a gateway in bytes per second.|
76
+
|**Gateway Inbound Flows**| Number of distinct 5-tuple flows (protocol, local IP address, remote IP address, local port, and remote port) flowing into a VPN Gateway. Limit is 250k flows.|
77
+
|**Gateway Outbound Flows**| Number of distinct 5-tuple flows (protocol, local IP address, remote IP address, local port, and remote port) flowing out of a VPN Gateway. Limit is 250k flows.|
78
+
|**Tunnel Bandwidth**| Average bandwidth of a tunnel in bytes per second.|
79
+
|**Tunnel Egress Bytes**| Outgoing bytes of a tunnel. |
80
+
|**Tunnel Egress Packets**| Outgoing packet count of a tunnel. |
81
+
|**Tunnel Ingress Bytes**| Incoming bytes of a tunnel.|
82
+
|**Tunnel Ingress Packet**| Incoming packet count of a tunnel.|
83
+
|**Tunnel Peak PPS**| Number of packets per second per link connection in the last minute.|
84
+
|**Tunnel Flow Count**| Number of distinct 3-tuple (protocol, local IP address, remote IP address) flows created per link connection.|
85
+
86
+
87
+
88
+
### <aname="p2s-metrics"></a>Supported metrics for microsoft.network/p2svpngateways
36
89
37
90
The following table lists the metrics available for the microsoft.network/p2svpngateways resource type.
### Supported metrics for microsoft.network/expressroutegateways
96
+
| Metric | Description|
97
+
| --- | --- |
98
+
|**Gateway P2S Bandwidth**| Average point-to-site aggregate bandwidth of a gateway in bytes per second. |
99
+
|**P2S Connection Count**|Point-to-site connection count of a gateway. To ensure you're viewing accurate Metrics in Azure Monitor, select the **Aggregation Type** for **P2S Connection Count** as **Sum**. You can also select **Max** if you split By **Instance**. |
100
+
| **User VPN Routes Count** | Number of User VPN Routes configured on the VPN gateway. This metric can be broken down into **Static** and **Dynamic** Routes.
101
+
102
+
### <aname="er-metrics"></a>Supported metrics for microsoft.network/expressroutegateways
44
103
45
104
The following table lists the metrics available for the microsoft.network/expressroutegateways resource type.
<!-- Repeat the following section for each resource type/namespace in your service.
87
-
<!-- Find the table(s) for the resource type in the Log Categories column at https://review.learn.microsoft.com/en-us/azure/azure-monitor/reference/supported-metrics/metrics-index?branch=main#supported-metrics-and-log-categories-by-resource-type.
88
-
-->
89
-
90
-
### Supported resource logs for microsoft.network/p2svpngateways
161
+
### <aname="p2s-diagnostic"></a>Supported resource logs for microsoft.network/p2svpngateways
### Supported resource logs for microsoft.network/vpngateways
165
+
The following diagnostics are available for Virtual WAN point-to-site VPN gateways:
166
+
167
+
| Metric | Description|
168
+
| --- | --- |
169
+
|**Gateway Diagnostic Logs**| Gateway-specific diagnostics such as health, configuration, service updates, and other diagnostics. |
170
+
|**IKE Diagnostic Logs**| IKE-specific diagnostics for IPsec connections.|
171
+
|**P2S Diagnostic Logs**| These are User VPN P2S (Point-to-site) configuration and client events. They include client connect/disconnect, VPN client address allocation, and other diagnostics.|
172
+
173
+
### <aname="s2s-diagnostic"></a>Supported resource logs for microsoft.network/vpngateways
|**Gateway Diagnostic Logs**| Gateway-specific diagnostics such as health, configuration, service updates, and additional diagnostics.|
180
+
|**Tunnel Diagnostic Logs**| These are IPsec tunnel-related logs such as connect and disconnect events for a site-to-site IPsec tunnel, negotiated SAs, disconnect reasons, and additional diagnostics. For connect and disconnect events, these logs also display the remote IP address of the corresponding on-premises VPN device.|
181
+
|**Route Diagnostic Logs**| These are logs related to events for static routes, BGP, route updates, and additional diagnostics. |
182
+
|**IKE Diagnostic Logs**| IKE-specific diagnostics for IPsec connections. |
Copy file name to clipboardExpand all lines: articles/virtual-wan/monitor-virtual-wan.md
+22Lines changed: 22 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -74,6 +74,28 @@ $MetricInformation.Data
74
74
75
75
For the available resource log categories, their associated Log Analytics tables, and the log schemas for Virtual WAN, see [Azure Virtual WAN monitoring data reference](monitor-virtual-wan-reference.md#resource-logs).
76
76
77
+
### Log Analytics sample query
78
+
79
+
If you selected to send diagnostic data to a Log Analytics Workspace, then you can use SQL-like queries, such as the following example, to examine the data. For more information, see [Log Analytics Query Language](/services-hub/health/log-analytics-query-language).
80
+
81
+
The following example contains a query to obtain site-to-site route diagnostics.
82
+
83
+
`AzureDiagnostics | where Category == "RouteDiagnosticLog"`
84
+
85
+
Replace the following values, after the **= =**, as needed based on the tables reported in the previous section of this article.
86
+
87
+
- "GatewayDiagnosticLog"
88
+
- "IKEDiagnosticLog"
89
+
- "P2SDiagnosticLog”
90
+
- "TunnelDiagnosticLog"
91
+
- "RouteDiagnosticLog"
92
+
93
+
In order to execute the query, you have to open the Log Analytics resource you configured to receive the diagnostic logs, and then select **Logs** under the **General** tab on the left side of the pane:
94
+
95
+
:::image type="content" source="./media/monitor-virtual-wan-reference/log-analytics-query-samples.png" alt-text="Screenshot of Log Analytics Query samples." lightbox="./media/monitor-virtual-wan-reference/log-analytics-query-samples.png":::
96
+
97
+
For Azure Firewall, a [workbook](../firewall/firewall-workbook.md) is provided to make log analysis easier. Using its graphical interface, you can investigate the diagnostic data without manually writing any Log Analytics query.
0 commit comments