Description
Flow logs record details such as traffic sources, destinations and allow or deny decisions to help investigate unusual communication and policy problems. When a required flow log is disabled, that collection path cannot produce new records. Flow logs do not replace packet capture or application logs.
New NSG flow logs cannot be created from June 30, 2025, and the feature retires on September 30, 2027. Review existing configurations and plan migration to Virtual Network flow logs.
Potential impact
- Unusual traffic or signs of compromise may be detected later.
- Evidence for investigating security-rule problems or tracing communication during an incident may be missing.
Remediation
- Configure supported flow logs for the required network scope and enable
enabled. Migrate existing NSG flow logs before retirement. - Check the storage account, collection permissions and retention policy, then test that real traffic records arrive.
- Integrate the records with monitoring and alerts, and manage access and cost.
Examples
These excerpts use an older AzureRM format to compare settings for an existing NSG flow log. The name and referenced resources are omitted. Do not use them to create a new NSG flow log today.
Before
resource "azurerm_network_watcher_flow_log" "example" {
network_watcher_name = azurerm_network_watcher.test.name
resource_group_name = azurerm_resource_group.test.name
network_security_group_id = azurerm_network_security_group.test.id
storage_account_id = azurerm_storage_account.test.id
enabled = false
retention_policy {
enabled = true
days = 7
}
}
Collection through this flow log is disabled. Also check whether another collection path records the required traffic.
After
resource "azurerm_network_watcher_flow_log" "example" {
network_watcher_name = azurerm_network_watcher.test.name
resource_group_name = azurerm_resource_group.test.name
network_security_group_id = azurerm_network_security_group.test.id
storage_account_id = azurerm_storage_account.test.id
enabled = true
retention_policy {
enabled = true
days = 7
}
}
This enables collection for the existing flow log. Seven days is an example retention period; check the required investigation window and the storage policy separately.