Azure Network Watcher flow logs are disabled

Collect the required network-traffic records with Azure Network Watcher flow logs.

Description

Flow logs record details such as traffic sources, destinations and allow or deny decisions to help investigate unusual communication and policy problems. When a required flow log is disabled, that collection path cannot produce new records. Flow logs do not replace packet capture or application logs.

New NSG flow logs cannot be created from June 30, 2025, and the feature retires on September 30, 2027. Review existing configurations and plan migration to Virtual Network flow logs.

Potential impact

  • Unusual traffic or signs of compromise may be detected later.
  • Evidence for investigating security-rule problems or tracing communication during an incident may be missing.

Remediation

  • Configure supported flow logs for the required network scope and enable enabled. Migrate existing NSG flow logs before retirement.
  • Check the storage account, collection permissions and retention policy, then test that real traffic records arrive.
  • Integrate the records with monitoring and alerts, and manage access and cost.

Examples

These excerpts use an older AzureRM format to compare settings for an existing NSG flow log. The name and referenced resources are omitted. Do not use them to create a new NSG flow log today.

Before

hcl
resource "azurerm_network_watcher_flow_log" "example" {
  network_watcher_name = azurerm_network_watcher.test.name
  resource_group_name  = azurerm_resource_group.test.name

  network_security_group_id = azurerm_network_security_group.test.id
  storage_account_id        = azurerm_storage_account.test.id
  enabled                   = false

  retention_policy {
    enabled = true
    days    = 7
  }
}

Collection through this flow log is disabled. Also check whether another collection path records the required traffic.

After

hcl
resource "azurerm_network_watcher_flow_log" "example" {
  network_watcher_name = azurerm_network_watcher.test.name
  resource_group_name  = azurerm_resource_group.test.name

  network_security_group_id = azurerm_network_security_group.test.id
  storage_account_id        = azurerm_storage_account.test.id
  enabled                   = true

  retention_policy {
    enabled = true
    days    = 7
  }
}

This enables collection for the existing flow log. Seven days is an example retention period; check the required investigation window and the storage policy separately.

References