Description
Flow logs help trace network communication and investigate security incidents. Deleting them before the required period ends can prevent later analysis of intrusion activity or unusual traffic. Disabling retentionPolicy differs from stopping flow log collection; actual retention also depends on storage deletion policies.
Potential impact
- Evidence of incident-time communication and impact may be unavailable.
- Network history required for audits or internal reviews may be missing.
Remediation
- Choose the period the organization needs and apply it through supported retentionPolicy and storage settings. Ninety days is an example target; verify actual collection and the oldest available records.
- Migrate existing NSG flow logs to Virtual Network flow logs before September 30, 2027. New NSG flow logs cannot be created; check retention and deletion policies during migration.
Examples
These excerpts compare retention settings only, omitting the target resource, storage and Network Watcher configuration. Retention for existing NSG flow logs requires a general-purpose v2 storage account.
Before
resource flowLog 'Microsoft.Network/networkWatchers/flowLogs@2020-11-01' = {
name: 'networkWatcher/flowlog'
location: resourceGroup().location
properties: {
enabled: true
retentionPolicy: {
enabled: false
days: 2
}
}
}
Collection is enabled but this retention policy is disabled, so days: 2 must not be interpreted as an active expiration period.
After
resource flowLog 'Microsoft.Network/networkWatchers/flowLogs@2020-11-01' = {
name: 'networkWatcher/flowlog'
location: resourceGroup().location
properties: {
enabled: true
retentionPolicy: {
enabled: true
days: 90
}
}
}
The retention policy is enabled with 90 days. Check that other storage policies do not delete records earlier.