Review Network Watcher flow log retention

Verify that actual flow records remain available for the required investigation period.

Description

Flow logs help trace network communication and investigate security incidents. Deleting them before the required period ends can prevent later analysis of intrusion activity or unusual traffic. Disabling retentionPolicy differs from stopping flow log collection; actual retention also depends on storage deletion policies.

Potential impact

  • Evidence of incident-time communication and impact may be unavailable.
  • Network history required for audits or internal reviews may be missing.

Remediation

  • Choose the period the organization needs and apply it through supported retentionPolicy and storage settings. Ninety days is an example target; verify actual collection and the oldest available records.
  • Migrate existing NSG flow logs to Virtual Network flow logs before September 30, 2027. New NSG flow logs cannot be created; check retention and deletion policies during migration.

Examples

These excerpts compare retention settings only, omitting the target resource, storage and Network Watcher configuration. Retention for existing NSG flow logs requires a general-purpose v2 storage account.

Before

bicep
resource flowLog 'Microsoft.Network/networkWatchers/flowLogs@2020-11-01' = {
  name: 'networkWatcher/flowlog'
  location: resourceGroup().location
  properties: {
    enabled: true
    retentionPolicy: {
      enabled: false
      days: 2
    }
  }
}

Collection is enabled but this retention policy is disabled, so days: 2 must not be interpreted as an active expiration period.

After

bicep
resource flowLog 'Microsoft.Network/networkWatchers/flowLogs@2020-11-01' = {
  name: 'networkWatcher/flowlog'
  location: resourceGroup().location
  properties: {
    enabled: true
    retentionPolicy: {
      enabled: true
      days: 90
    }
  }
}

The retention policy is enabled with 90 days. Check that other storage policies do not delete records earlier.

References