Review Azure flow-log retention

Check the flow-log retention needed for investigations and the storage account’s actual deletion policies.

Description

If flow-log retention is too short, network records may already be deleted when an incident is discovered. Set retention according to the organization’s investigation and audit needs; 90 days is not sufficient for every environment.

Disabling a retention policy is different from stopping flow-log collection. Check both flow-log settings and storage lifecycle or deletion policies to establish how long records actually remain available.

Potential impact

  • Evidence of communication during an incident may be missing.
  • Long-term traffic comparisons and audit evidence can be incomplete.

Remediation

  • Define the required period and apply it through supported retention_policy settings and storage policies.
  • Verify collection and the oldest available records, and check for other policies that delete logs earlier. Manage access and cost as well.
  • New NSG flow logs cannot be created from June 30, 2025. Migrate existing logs to Virtual Network flow logs before retirement on September 30, 2027, and review retention as part of that migration.

Examples

These excerpts use an older AzureRM format to compare retention for an existing NSG flow log. The name and referenced resources are omitted. They are not examples for creating a new NSG flow log today.

Before

hcl
resource "azurerm_network_watcher_flow_log" "example" {
  network_watcher_name     = azurerm_network_watcher.test.name
  resource_group_name      = azurerm_resource_group.test.name
  network_security_group_id = azurerm_network_security_group.test.id
  storage_account_id        = azurerm_storage_account.test.id
  enabled                   = true

  retention_policy {
    enabled = true
    days    = 89
  }
}

An 89-day period is one day short if the organization requires 90 days. This number alone does not establish the actual investigation window.

After

hcl
resource "azurerm_network_watcher_flow_log" "example" {
  network_watcher_name      = azurerm_network_watcher.test.name
  resource_group_name       = azurerm_resource_group.test.name
  network_security_group_id = azurerm_network_security_group.test.id
  storage_account_id        = azurerm_storage_account.test.id
  enabled                   = true

  retention_policy {
    enabled = true
    days    = 90
  }
}

The period is increased to the example baseline of 90 days. This does not recover previously deleted logs; verify actual storage and investigation requirements.

References