Azure: Enable NSG Flow Logs
To enable Azure VPC flow logs, follow the below steps.
Procedure
1 |
In the Security Cloud Control platform menu, choose . |
2 |
Go to the Resource Groups section in Azure portal. |
3 |
Click the Create button. |
4 |
Choose the subscription and provide a name for this new resource group. |
5 |
Select a Region. (example: (US) East US). |
6 |
Click the Review + create button. |
7 |
Go to the storage accounts section and click the Create button. |
8 |
Select the Subscription and Resource group that was just created. |
9 |
Select the same region as the resource group. |
10 |
Provide a name for the storage account. Note that Redundancy cannot be locally-redundant storage(LRS) |
11 |
Click the Review + create button. This creates a storage account where NSG flow logs are stored. |
12 |
Go to the Subscription section and find the subscription that was recently created. |
13 |
Navigate to Resource Providers. |
14 |
Ensure that the |
15 |
Go to the Network Watcher section. |
16 |
Click Add and add the regions that you want NSG flow logs to be enabled for. |
17 |
Go to . |
18 |
Create flow logs for the NSG where you want to enable NSG flow log. Provide the storage account created above. Set the Retention days as 30. |
19 |
Navigate to the storage account created and click on Events. |
20 |
Click Event Subscription. |
21 |
Provide a name for this event subscription. |
22 |
Select the resource group that was created above. |
23 |
Provide a System Topic Name. |
24 |
For Filter to Event Types, the default value is Blob Created and Blob Deleted. |
25 |
For Endpoint Type, select Web Hook. |
26 |
Click the Select an endpoint link. The Subscriber Endpoint is |