You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/network-watcher/network-watcher-nsg-flow-logging-overview.md
+9-9Lines changed: 9 additions & 9 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -20,7 +20,7 @@ ms.author: damendo
20
20
21
21
## Introduction
22
22
23
-
[Network security group](https://docs.microsoft.com/azure/virtual-network/security-overview#security-rules) (NSG) flow logs is a feature of Azure Network Watcher that allows you to log information about IP traffic flowing through an NSG. Flow data is sent to Azure Storage accounts from where you can access it as well as export it to any visualization tool, SIEM or IDS of your choice.
23
+
[Network security group](https://docs.microsoft.com/azure/virtual-network/security-overview#security-rules) (NSG) flow logs is a feature of Azure Network Watcher that allows you to log information about IP traffic flowing through an NSG. Flow data is sent to Azure Storage accounts from where you can access it as well as export it to any visualization tool, SIEM, or IDS of your choice.
@@ -48,7 +48,7 @@ Flow logs are the source of truth for all network activity in your cloud environ
48
48
- Logs are collected through the Azure platform and do not affect customer resources or network performance in any way.
49
49
- Logs are written in the JSON format and show outbound as well as inbound flows on a per NSG rule basis.
50
50
- Each log record contains the network interface (NIC) the flow applies to, 5-tuple information, the traffic decision & (Version 2 only) throughput information. See _Log Format_ below for full details.
51
-
- Flow Logs have a retention feature that allows auto-deleting the logs up to a year after their creation
51
+
- Flow Logs have a retention feature that allows automatically deleting the logs up to a year after their creation
52
52
53
53
**Core concepts**
54
54
@@ -57,7 +57,7 @@ Flow logs are the source of truth for all network activity in your cloud environ
57
57
- All traffic flows in your network are evaluated using the rules in the applicable NSG.
58
58
- The result of these evaluations is NSG Flow Logs. Flow logs are collected through the Azure platform and do not require any change to the customer resources.
59
59
- NSG Flow Logs are written to storage accounts from where they can be accessed.
60
-
- You can export, process, analyze and visualize Flow Logs using tools like TA, Splunk, Grafana, Stealthwatch, etc.
60
+
- You can export, process, analyze, and visualize Flow Logs using tools like TA, Splunk, Grafana, Stealthwatch, etc.
**Enable on critical VNETs/Subnets**: Flow Logs should be enabled on all critical VNETs/subnets in your subscription as an auditability and security best practice.
360
360
361
-
**Enable NSG Flow Logging on all NSGs attached to a resource**: Flow logging in Azure is configured on the NSG resource. A flow will only be associated to one NSG Rule. In scenarios where multiple NSGs are utilized, we recommend that NSG flow logging is enabled on all NSGs applied a resource's subnet or network interface to ensure that all traffic is recorded. For more information see [how traffic is evaluated](../virtual-network/security-overview.md#how-traffic-is-evaluated) in Network Security Groups.
361
+
**Enable NSG Flow Logging on all NSGs attached to a resource**: Flow logging in Azure is configured on the NSG resource. A flow will only be associated to one NSG Rule. In scenarios where multiple NSGs are utilized, we recommend that NSG flow logging is enabled on all NSGs applied a resource's subnet or network interface to ensure that all traffic is recorded. For more information, see [how traffic is evaluated](../virtual-network/security-overview.md#how-traffic-is-evaluated) in Network Security Groups.
362
362
363
363
**Storage provisioning**: Storage should be provisioned in tune with expected Flow Log volume.
- **Microsoft.Insights** resource provider is not registered
370
370
371
-
If you received an _AuthorizationFailed_ or a _GatewayAuthenticationFailed_ error, you might have not enabled the Microsoft Insights resource provider on your subscription. Please [follow the instructions](https://docs.microsoft.com/azure/network-watcher/network-watcher-nsg-flow-logging-portal#register-insights-provider) to enable the Microsoft Insights provider.
371
+
If you received an _AuthorizationFailed_ or a _GatewayAuthenticationFailed_ error, you might have not enabled the Microsoft Insights resource provider on your subscription. [Follow the instructions](https://docs.microsoft.com/azure/network-watcher/network-watcher-nsg-flow-logging-portal#register-insights-provider) to enable the Microsoft Insights provider.
372
372
373
373
### **I have enabled NSG Flow Logs but do not see data in my storage account**
374
374
@@ -400,23 +400,23 @@ To use a Storage account behind a firewall, you have to provide an exception for
400
400
401
401
- Navigate to the storage account by typing the storage account's name in the global search on the portal or from the [Storage Accounts page](https://ms.portal.azure.com/#blade/HubsExtension/BrowseResource/resourceType/Microsoft.Storage%2FStorageAccounts)
402
402
- Under the **SETTINGS** section, select **Firewalls and virtual networks**
403
-
- In **Allow access from**, select **Selected networks**. Then under **Exceptions**, tick the box next to ****Allow trusted Microsoft services to access this storage account****
403
+
- In **Allow access from**, select **Selected networks**. Then under **Exceptions**, tick the box next to ****Allow trusted Microsoft services to access this storage account****
404
404
- If it is already selected, no change is needed.
405
405
- Locate your target NSG on the [NSG Flow Logs overview page](https://ms.portal.azure.com/#blade/Microsoft_Azure_Network/NetworkWatcherMenuBlade/flowLogs) and enable NSG Flow Logs with the above storage account selected.
406
406
407
407
You can check the storage logs after a few minutes, you should see an updated TimeStamp or a new JSON file created.
408
408
409
409
### **How do I use NSG Flow Logs with a Storage account behind a Service Endpoint?**
410
410
411
-
NSG Flow Logs are compatible with Service Endpoints without requiring any extra configuration. Please see the [tutorial on enabling Service Endpoints](https://docs.microsoft.com/azure/virtual-network/tutorial-restrict-network-access-to-resources#enable-a-service-endpoint) in your virtual network.
411
+
NSG Flow Logs are compatible with Service Endpoints without requiring any extra configuration. See the [tutorial on enabling Service Endpoints](https://docs.microsoft.com/azure/virtual-network/tutorial-restrict-network-access-to-resources#enable-a-service-endpoint) in your virtual network.
412
412
413
413
### **What is the difference between flow logs versions 1 & 2?**
414
414
415
415
Flow Logs version 2 introduces the concept of _Flow State_ & stores information about bytes and packets transmitted. [Read more](https://docs.microsoft.com/azure/network-watcher/network-watcher-nsg-flow-logging-overview#log-file)
416
416
417
417
## Pricing
418
418
419
-
NSG Flow Logs are charged per GB of logs collected and comes with free tier of 5 GB/month per subscription. For the current pricing in your region, please see the [Network Watcher pricing page](https://azure.microsoft.com/pricing/details/network-watcher/).
419
+
NSG Flow Logs are charged per GB of logs collected and come with a free tier of 5 GB/month per subscription. For the current pricing in your region, see the [Network Watcher pricing page](https://azure.microsoft.com/pricing/details/network-watcher/).
420
420
421
-
Storage of logs is charged separately, please see [Azure Storage Block blob pricing page](https://azure.microsoft.com/pricing/details/storage/blobs/) for relevant prices.
421
+
Storage of logs is charged separately, see [Azure Storage Block blob pricing page](https://azure.microsoft.com/pricing/details/storage/blobs/) for relevant prices.
0 commit comments