Configure Azure VNet Flow Logs
Azure VNet Flow Logs brings Azure virtual network flow log data into SolarWinds Observability SaaS, enabling you to monitor and investigate Layer 4 (L4) network traffic across your Azure infrastructure alongside Configure AWS VPC Flow Logs and on-premises NTA data.
How VNet Flow ingestion works
VNet Flow Logs is a capability of Azure Network Watcher that records IP traffic flowing through a virtual network (VNet), in the same way that AWS VPC Flow Logs record traffic for a VPC. Azure writes the flow records to a storage account as JSON blobs.
SolarWinds Observability SaaS ingests the flow logs through a SolarWinds-provided Azure Function that you deploy into your own Azure subscription. The function reads the flow log blobs from your storage account, parses them, and forwards the data to the SolarWinds Observability SaaS OTel ingestion endpoint using an ingestion API token. The data is then available on the Flows tab of the Azure subscription's entity details page.
Prerequisites
-
An Azure subscription connected to SolarWinds Observability SaaS. See Add an Azure cloud account.
-
Permissions in Azure to create a VNet flow log, create a storage account, and deploy an Azure Function (Function App).
-
A SolarWinds Observability SaaS ingestion API token, or permission to create one.
VNet Flow ingestion setup
Complete the following tasks to configure VNet Flow Logs for a monitored Azure cloud account.
Task 1: Create a flow log and storage account in Azure
To monitor flows in SolarWinds Observability SaaS, you first need a flow log resource in your virtual network and a storage account to hold the flow log data.
-
In the Azure portal, open Network Watcher.
-
Select Flow Logs and click Create.
-
Select the target virtual network, and then select or create a storage account for the flow log data.
-
Enable the flow log and set a retention period.
Task 2: Open the setup dialog
-
In the left pane of SolarWinds Observability SaaS, click Infrastructure > Azure.
-
Click the name of a monitored Azure cloud account.
-
Click the Flows tab.
If the VNet Flow Logs have not been configured, the Flows tab contains a message that Azure VNet Flow Logs are unavailable, and it displays the Configure Azure VNet Flows button.
-
Click the Configure Azure VNet Flows button to open the setup dialog.
The setup dialog is a single scrolling dialog. The following tasks provide instructions for completing each section of the dialog.
Task 3: Get an ingestion API token
In the Get Ingestion Token section of the setup dialog, do one of the following:
-
Select Use Existing Token, and choose a token from your organization.
-
Select Generate New Token, provide a token name, and click Generate Token.
You will paste the token value into the Api Token field of the Azure deployment form in a later task.
Task 4: Get an OTLP endpoint
In the Get OTLP Endpoint section of the setup dialog, verify that the value in the OTLP Endpoint field matches your organization’s cluster (for example, otel.collector.na-01.cloud.solarwinds.com:443). See Data centers and endpoint URIs for more information.
You will paste the OTLP value into the Otlp Endpoint field of the Azure deployment form in the next task.
Task 5: Deploy the SolarWinds Azure function
-
In the SolarWinds Observability SaaS setup dialog, click Deploy new function in Azure. The Azure portal opens on the custom template deployment page.
-
Complete the deployment form.
Field Description Subscription / Resource group The Azure subscription and resource group to deploy the function into. Region The Azure region for the Function App. Function App Name A name for the new Function App. Storage Account Name The storage account created in task 1, which receives the flow log blobs. Otlp Endpoint The SolarWinds Observability SaaS OTel ingestion endpoint.
In the setup dialog, click the clipboard button in the OTLP Endpoint field to copy this value, and then paste it into the Azure deployment form.
Api Token The ingestion API token.
In the setup dialog, click the clipboard button in the API Token field to copy this value, and then paste it into the Azure deployment form.
-
Click Review + create, and then click Create. Azure provisions a Function App that reads the flow log blobs and forwards them to SolarWinds Observability SaaS.
Task 6: Confirm the function is deployed
Return to the setup dialog in SolarWinds Observability SaaS. In the Set up log forwarding in Azure section, click the refresh button
.
The Deployed Functions table lists deployed functions with their name, version, and status.
-
The Version column specifies the version number and whether it is current:
-
Up To Date: The function is forwarding data on the current version.
-
Outdated: A newer version of the function template is available.
-
-
The Status column specifies whether the function is currently running or stopped.
Until a function is found, the section shows a Deploy New Function in Azure button instead.
To open the Function App in the Azure portal, click View in Azure.
VNet Flow Log record fields
Each Azure VNet Flow Log record ingested into SolarWinds Observability SaaS includes the following fields. The VNet Flow Logs table shows the core fields as columns by default. The remaining fields, covering country, ACL, encryption, and resource identifiers, are available as filter and search attributes.
| Field | Description |
|---|---|
| Source Address | Source IP address of the flow. |
| Destination Address | Destination IP address of the flow. |
| Source Port | Source port of the flow. |
| Destination Port | Destination port of the flow. |
| Protocol | Transport protocol, for example TCP or UDP. |
| Action | Whether the flow was accepted or denied. |
| Flow Direction | Direction of the flow, either ingress or egress. |
| Flow State | State of the flow record as reported by Azure: B for begin, C for continuing, and E for end. |
| MAC Address | MAC address of the network interface associated with the flow. |
| VNet ID | Identifier of the virtual network the flow belongs to. |
| Region | Azure region the flow was recorded in. |
| Bytes | Number of bytes transferred. |
| Packets | Number of packets transferred. |
| Access Control List ID | Identifier of the network security group (NSG) or ACL that evaluated the flow. |
| Source Country | Country resolved from the source IP address. |
| Destination Country | Country resolved from the destination IP address. |
| Flow Encryption | Encryption status of the flow as reported by Azure. |
| Flow Source | Origin of the flow log record. |
| Rule | Name of the security rule that matched the flow. |
| Flow Log GUID | Globally unique identifier of the flow log record. |
| Flow Log Resource ID | Azure resource ID of the flow log resource that produced the record. |
| Target Resource ID | Azure resource ID of the virtual network the flow log is attached to. |
Verify your configuration
After the function is deployed and running, the first flow records can take a few minutes to arrive. Open the Flows tab for the Azure subscription and confirm that the Traffic Flow chart, the top-metrics widgets, and the VNet Flow Logs table contain data, as described in the Flows tab section below.
Reconfiguring the VNet Flow Logs integration
To review deployed functions, generate a new ingestion token, or add coverage for another VNet or storage account, open the setup dialog again. On the Flows tab, click the vertical ellipsis in the upper-right corner of the tab and select Configure Flows.
The dialog lists every function already tagged for VNet Flow Logs across the subscription, so you can confirm their status without changing anything.
SolarWinds Observability SaaS does not reconfigure existing functions in place. Manage or remove them in the Azure portal. To extend coverage to another VNet or storage account, click Deploy new function in Azure and repeat the deployment steps.
Removing the integration
To stop sending VNet Flow Logs data to SolarWinds Observability SaaS, delete the deployed Function App and its associated resources in the Azure portal. To navigate there, use View in Azure in the functions table.
Removing the flow log resource in Network Watcher stops Azure from generating new flow log blobs.
View data on the Flows tab
To open the Flows tab:
-
In the left pane, click Infrastructure > Azure.
-
Click the name of a monitored Azure cloud account.
-
Click the Flows tab.
The tab displays the following widgets for the selected time window and filters.
Traffic Flow
A Sankey chart visually represents the top traffic flows from source address, through protocol and action, to destination port.
Top traffic widgets
The Top 10 Accepted Traffic by Interface widget ranks interfaces by accepted traffic volume, and the Top 10 Rejected Traffic widget ranks interfaces by the number of rejected flow records. The Top 5 Ingress and Egress Traffic by Subnet widget compares inbound and outbound traffic for each subnet.
Top Countries maps
The Top Countries - Accepted Traffic map ranks accepted traffic by country, and the Top Countries - Rejected Traffic map ranks rejected traffic by country.
VNet Flow Logs table
A paginated table of flow log records containing the VNet Flow Log record fields. Every column is sortable and the page size is configurable. The table is sorted by Bytes in descending order by default.
Filtering and search
Use the filter toolbar above the widgets to narrow down the data. Quick filters are provided for Source Address, Protocol, Action, and Destination Port, and the Filters button opens the full filter set. Use the control on the right to toggle between Basic and Query mode.
In Query mode, the search box supports queries such as the following.
| Example | Description |
|---|---|
srcaddr:10.0.0.1
|
Search by source address. |
protocol:TCP
|
Search by protocol. |
action:ACCEPT
|
Search by action, to show accepted or rejected traffic. |
dstport:443
|
Search by destination port. |
Performance
The Azure Function that forwards VNet Flow Logs runs in your own Azure subscription and is subject to the standard Azure Functions limits on execution duration, memory, and concurrency.
Troubleshooting
| Message | Cause and resolution |
|---|---|
| VNet Flow Logs data is unavailable for this Azure subscription. To collect logs, enable the Azure integration. | The Azure subscription integration is disabled. Click Go to Azure Account Settings and enable the Azure integration. |
| Data is unavailable. Make sure the Azure VNet Flow Logs function is deployed and configured for this subscription. | No function has been deployed yet. Open Configure Azure VNet Flows and deploy the function as described in VNet Flow ingestion setup. |
| Data is unavailable for the selected time period. | A function is configured, but no data arrived for the selected window. Verify that the function's status in the configuration dialog is Running or Up to date, check the Function App logs in the Azure portal, and try widening the time window. |
| No VNet Flow Logs match the current filters. | Data is being collected, but no records match the current filters or time window. Adjust the filters or expand the time window. |
| Rejected traffic always shows 0 bytes and 0 packets. | This is expected. Azure deny-flow log entries never report byte or packet counters, so the rejected-traffic widgets rank by flow count instead. |