|
| 1 | +--- |
| 2 | +title: Configure event logs for Azure Virtual Network Manager |
| 3 | +description: This article describes how to configure and view event logs for Azure Virtual Network Manager. This includes how to access event logs in a Log Analytics workspace and a storage account. |
| 4 | +author: mbender-ms |
| 5 | +ms.author: mbender |
| 6 | +ms.topic: how-to |
| 7 | +ms.service: virtual-network-manager |
| 8 | +ms.date: 04/13/2023 |
| 9 | +--- |
| 10 | + |
| 11 | +# Configure event logs for Azure Virtual Network Manager |
| 12 | + |
| 13 | +When configurations are changed in Azure Virtual Network Manager, this can affect virtual networks that are associated with network groups in your instance. With Azure Monitor, you can monitor Azure Virtual Network Manager for virtual network changes. |
| 14 | + |
| 15 | +In this article, you learn how to monitor Azure Virtual Network Manager for virtual network changes with Log Analytics or a storage account. |
| 16 | + |
| 17 | +## Prerequisites |
| 18 | +- An Azure account with an active subscription. [Create an account for free](https://azure.microsoft.com/free/?WT.mc_id=A261C142F). |
| 19 | +- A deployed instance of [Azure Virtual Network Manager](./create-virtual-network-manager-portal.md) in your subscription, with managed virtual networks. |
| 20 | +- You deployed either a [Log Analytics workspace](../azure-monitor/essentials/tutorial-resource-logs.md#create-a-log-analytics-workspace) or a [storage account](../storage/common/storage-account-create.md) to store event logs and observe data related to Azure Virtual Network Manager. |
| 21 | + |
| 22 | +## Configure Diagnostic Settings |
| 23 | + |
| 24 | +Depending on how you consume event logs, you need to set up a Log Analytics workspace or a storage account for storing your log events. These are as storage targets when configuring diagnostic settings for Azure Virtual Network Manager. Once you have configured your diagnostic settings, you can view the event logs in the Log Analytics workspace or storage account. |
| 25 | + |
| 26 | +> [!NOTE] |
| 27 | +> At least one virtual network must be added or removed from a network group in order to generate logs. A log will generate for this event a couple minutes after network group membership change occurs. |
| 28 | +### Configure event logs with Log Analytics |
| 29 | + |
| 30 | +Log analytics is one option for storing event logs. In this task, you configure your Azure Virtual Network Manager Instance to use a Log Analytics workspace. This task assumes you have already deployed a Log Analytics workspace. If you haven't, see [Create a Log Analytics workspace](../azure-monitor/essentials/tutorial-resource-logs.md#create-a-log-analytics-workspace). |
| 31 | + |
| 32 | +1. Navigate to the network manager you want to obtain the logs of. |
| 33 | +1. Under the **Monitoring** in the left pane, select the **Diagnostic settings**. |
| 34 | +1. Select **+ Add diagnostic setting** and enter a diagnostic setting name. |
| 35 | +1. Under **Logs**, select **Network Group Membership Change**. |
| 36 | +1. Under **Destination details**, select **Send to Log Analytics** and choose your subscription and Log Analytics workspace from the dropdown menus. |
| 37 | + |
| 38 | + :::image type="content" source="media/how-to-configure-event-logging/log-analytics-diagnostic-settings.png" alt-text="Screenshot of Diagnostic settings page for setting up Log Analytics workspace."::: |
| 39 | + |
| 40 | +1. Select **Save** and close the window. |
| 41 | + |
| 42 | +### Configure event logs with a storage account |
| 43 | + |
| 44 | +A storage account is another option for storing event logs. In this task, you configure your Azure Virtual Network Manager Instance to use a storage account. This task assumes you have already deployed a storage account. If you haven't, see [Create a storage account](../storage/common/storage-account-create.md). |
| 45 | + |
| 46 | +1. Navigate to the network manager you want to obtain the logs of. |
| 47 | +1. Under the **Monitoring** in the left pane, select the **Diagnostic settings**. |
| 48 | +1. Select **+ Add diagnostic setting** and enter a diagnostic setting name. |
| 49 | +1. Under **Destination details**, select **Send to storage account** and choose your subscription and storage account from the dropdown menus. |
| 50 | +1. Under **Logs**, select **Network Group Membership Change** and enter a retention period. |
| 51 | + |
| 52 | + :::image type="content" source="media/how-to-configure-event-logging/storage-account-diagnostic-settings.png" alt-text="Screenshot of Diagnostic settings for storage account."::: |
| 53 | + |
| 54 | +1. Select **Save** and close the window. |
| 55 | + |
| 56 | +## View Azure Virtual Network Manager event logs |
| 57 | + |
| 58 | +In this task, you access the event logs for your Azure Virtual Network Manager instance. |
| 59 | + |
| 60 | +1. Under the **Monitoring** in the left pane, select the **Logs**. |
| 61 | +1. In the **Diagnostics** window, select **Run** or **Load to editor** under **Get recent Network Group Membership Changes**. |
| 62 | + |
| 63 | + :::image type="content" source="media/how-to-configure-event-logging/run-query.png" alt-text="Screenshot of Run and Load to editor buttons in the diagnostics window."::: |
| 64 | + |
| 65 | +1. If you choose **Run**, the **Results** tab displays the event logs, and you can expand each log to view the details. |
| 66 | + |
| 67 | + :::image type="content" source="media/how-to-configure-event-logging/workspace-log-details.png" alt-text="Screenshot of the event log details from the defined query."::: |
| 68 | + |
| 69 | +1. When completed reviewing the logs, close the window and select **ok** to discard changes. |
| 70 | + |
| 71 | + > [!NOTE] |
| 72 | + > When you close the **Query editor** window, you will be be returned to the **Azure Home** page. If you need to return to the **Logs** page, browse to your virtual network manager instance, and select **Logs** under the **Monitoring** in the left pane. |
| 73 | +
|
| 74 | +1. If you choose **Load to editor**, the **Query editor** window displays the query. Choose **Run** to display the event logs and you can expand each log to view the details. |
| 75 | + |
| 76 | + :::image type="content" source="media/how-to-configure-event-logging/workspace-log-details.png" alt-text="Screenshot of log details."::: |
| 77 | +1. Close the window and select **ok** to discard changes. |
| 78 | + |
| 79 | +## Next steps |
| 80 | + |
| 81 | +- Learn about [Security admin rules](concept-security-admins.md) |
| 82 | +- Learn how to [Use queries in Azure Monitor Log Analytics](../azure-monitor/logs/queries.md) |
| 83 | +- Learn how to block network traffic with a [SecurityAdmin configuration](how-to-block-network-traffic-portal.md). |
0 commit comments