π‘οΈ Azure Virtual Network Flow Logs are not captured and sent to Log Analytics Workspaceπ’βͺ
- Contextual name: π‘οΈ Virtual Network Flow Logs are not captured and sent to Log Analytics Workspaceπ’βͺ
- ID:
/ce/ca/azure/network-watcher/virtual-network-flow-logs - Tags:
- βͺ Impossible policy
- π’ Policy with categories
- π’ Policy with type
- Policy Type:
COMPLIANCE_POLICY - Policy Categories:
SECURITY,RELIABILITY
Descriptionβ
Descriptionβ
Ensure that virtual network flow logs are captured and fed into a central log analytics workspace.
Rationaleβ
Virtual network flow logs provide critical visibility into traffic patterns. Sending logs to a Log Analytics workspace enables centralized analysis, correlation, and alerting for faster threat detection and response.
Impactβ
- Virtual network flow logs are charged per gigabyte of network flow logs collected and come with a free tier of 5 GB/month per subscription.
- If traffic analytics is enabled with virtual network flow logs, traffic analytics pricing applies at per gigabyte processing rates.
- The storage of logs is charged separately.
Auditβ
From Azure Portalβ
- Go to
Network Watcher.- Under
Logs, selectFlow logs.- Click
Add filter.- From the
Filterdrop-down menu, selectFlow log type.- From the
Valuedrop-down menu, checkVirtual networkonly.- Click
Apply.- Ensure that at least one virtual network flow log is listed and is configured to send logs to a
Log Analytics Workspace.... see more
Remediationβ
Remediationβ
From Azure Portalβ
- Navigate to
Network Watcher.- Under
Logs, selectFlow logs.- Select
+ Create.- Select a subscription.
- Next to
Flow log type, selectVirtual network.- Click +
Select target resource.- Select
Virtual network.- Select a virtual network.
- Click
Confirm selection.- Select a storage account, or create a new storage account.
- Set the retention in days for the storage account.
- Click
Next.- Under
Analytics, forFlow logs version, selectVersion 2.- Check the box next to
Enable traffic analytics.- Select a processing interval.
- Select a
Log Analytics Workspace.- Click
Next.- Optionally, add
Tags.- Click
Review + create.- Click
Create.- Repeat steps 1-20 for each subscription or virtual network requiring remediation.
policy.yamlβ
Linked Framework Sectionsβ
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|---|---|---|---|---|
| πΌ CIS Azure v4.0.0 β πΌ 7.1.1.7 Ensure that virtual network flow logs are captured and sent to Log Analytics (Manual) | 1 | no data | |||
| πΌ Cloudaware Framework β πΌ Logging and Monitoring Configuration | 65 | no data |