Network watcher NSG Flow logs

Amar-Azure-Practice 656 Reputation points
2022-09-08T03:22:44.693+00:00

Hi

I have enabled NSG flow logs on Azure Network watcher service for 2 NSG services (NGS-1 and NSG-2).

I have 2 Subnets

              Subnet is associated to Outbound for an Azure function (Azure function with App Service plan) -- This Subnet is assigned to NSG-1  

               Subnet is assigned to Inbound for Azure function (Same Azure function as above)--This Subnet is assigned to NSG-2  

does the NSG flow logs capture all the IP traffic flowing through an NSG?

Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,177 questions
Azure Network Watcher
Azure Network Watcher
An Azure service that is used to monitor, diagnose, and gain insights into network performance and health.
159 questions
0 comments No comments
{count} votes

Accepted answer
  1. KapilAnanth-MSFT 35,581 Reputation points Microsoft Employee
    2022-09-09T14:45:31.703+00:00

    Hi @Amar-Azure-Practice ,

    Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.
    I understand that you would like to understand more about NSG flow logging for Azure Functions with ASP Plan.

    Currently, ASP plan does not support NSG flow logging.

    Refer : https://learn.microsoft.com/en-us/azure/network-watcher/network-watcher-nsg-flow-logging-overview#nsg-flow-logging-considerations
    239516-image.png

    Though these subnets are configured for outbound and inbound, as the document states, NSG flow logging will not be feasible.

    Please do let us know if you require additional queries on this.

    Cheers,
    Kapil

    ----------------------------------------------------------------------------------------------------------------

    Please don’t forget to close the thread by clicking "Accept the answer" wherever the information provided helps you, as this can be beneficial to other community members.

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Maxim Sergeev 6,566 Reputation points Microsoft Employee
    2022-09-08T03:31:35.907+00:00

    Hi @Amar-Azure-Practice ,

    Yes, if the traffic goes through NSG-1 and NSG-2 only