π Azure Virtual Network Flow Logs are not captured and sent to Log Analytics Workspace π’
- Contextual name: π Virtual Network Flow Logs are not captured and sent to Log Analytics Workspace π’
- ID:
/ce/ca/azure/network-watcher/virtual-network-flow-logs
- Located in: π Azure Network Watcher
Flagsβ
- π’ Impossible policy
- π’ Policy with categories
- π’ Policy with type
Our Metadataβ
- Policy Type:
COMPLIANCE_POLICY
- Policy Category:
SECURITY
RELIABILITY
Descriptionβ
Descriptionβ
Ensure that virtual network flow logs are captured and fed into a central log analytics workspace.
Rationaleβ
Virtual network flow logs provide critical visibility into traffic patterns. Sending logs to a Log Analytics workspace enables centralized analysis, correlation, and alerting for faster threat detection and response.
Impactβ
- Virtual network flow logs are charged per gigabyte of network flow logs collected and come with a free tier of 5 GB/month per subscription.
- If traffic analytics is enabled with virtual network flow logs, traffic analytics pricing applies at per gigabyte processing rates.
- The storage of logs is charged separately.
Auditβ
From Azure Portalβ
- Go to
Network Watcher
.- Under
Logs
, selectFlow logs
.- Click
Add filter
.- From the
Filter
drop-down menu, selectFlow log type
.- From the
Value
drop-down menu, checkVirtual network
only.- Click
Apply
.- Ensure that at least one virtual network flow log is listed and is configured to send logs to a
Log Analytics Workspace
.... see more
Remediationβ
Remediationβ
From Azure Portalβ
- Navigate to
Network Watcher
.- Under
Logs
, selectFlow logs
.- Select
+ Create
.- Select a subscription.
- Next to
Flow log type
, selectVirtual network
.- Click +
Select target resource
.- Select
Virtual network
.- Select a virtual network.
- Click
Confirm selection
.- Select a storage account, or create a new storage account.
- Set the retention in days for the storage account.
- Click
Next
.- Under
Analytics
, forFlow logs version
, selectVersion 2
.- Check the box next to
Enable traffic analytics
.- Select a processing interval.
- Select a
Log Analytics Workspace
.- Click
Next
.- Optionally, add
Tags
.- Click
Review + create
.- Click
Create
.- Repeat steps 1-20 for each subscription or virtual network requiring remediation.
policy.yamlβ
Linked Framework Sectionsβ
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ CIS Azure v4.0.0 β πΌ 7.1.1.7 Ensure that virtual network flow logs are captured and sent to Log Analytics (Manual) | 1 | |||
πΌ Cloudaware Framework β πΌ Logging and Monitoring Configuration | 59 |