Queries for the AZFWFatFlow table
For information on using these queries in the Azure portal, see Log Analytics tutorial. For the REST API, see Query.
Azure Firewall Top Flow Logs
Identify top flows across Azure Firewall instances. Log contains flow information, date transmission rate (in Megabits per second units) and the time period when the flows were recorded.
// Get the fatflows from past 1000 samples with rate atleast 5 mbps
AZFWFatFlow
| take 1000
| order by TimeGenerated desc
| where FlowRate > 5