Information
Ensure that virtual network flow logs are captured and fed into a central log analytics workspace.
Virtual network flow logs provide critical visibility into traffic patterns. Sending logs to a Log Analytics workspace enables centralized analysis, correlation, and alerting for faster threat detection and response.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
Remediate from Azure Portal
- Go to Network Watcher
- Under Logs click Flow logs
- Click + Create
- Select a subscription.
- Next to Flow log type select Virtual network
- Click + Select target resource
- Select Virtual network
- Select a virtual network.
- Click Confirm selection
- Select a storage account, or create a new storage account.
- Set the retention in days for the storage account.
- Click Next
- Under Analytics for Flow logs version select Version 2
- Check the box next to Enable traffic analytics
- Select a processing interval.
- Select a Log Analytics Workspace
- Click Next
- Optionally, add Tags
- Click Review + create
- Click Create
- Repeat steps 1-20 for each subscription or virtual network requiring remediation.
Impact:
- Virtual network flow logs are charged per gigabyte of network flow logs collected and come with a free tier of 5 GB/month per subscription.
- If traffic analytics is enabled with virtual network flow logs, traffic analytics pricing applies at per gigabyte processing rates.
- The storage of logs is charged separately.