Hi,
I believe a Kusto query like this should serve your purpose when you run it on your Log Analytics workspace
AzureNetworkAnalytics_CL
| where SubType_s == "FlowLog"
| where FlowDirection_s == "I"
| where VM2_s == "<resource group name>/<vm name>"
| where DestPort_d == 443
| extend AllowedBlocked = iff(AllowedInFlows_d > 0, 'Allowed', iff(DeniedInFlows_d >0, 'Blocked', 'Unknown') )
You either have to choose time range from UI or add it within the query. You will also have to fill in the details of your VM within the query. Column Country_s will give you the location. Column L7Protocol_s will give you the protocol used. You can find the whole schema for Traffic Analysis documented here in case you need further information that is available within it. I have made it easier for you to see if a traffic flow is allowed or blocked.
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.