Description
If flow-log retention is too short, network records may already be deleted when an incident is discovered. Set retention according to the organization’s investigation and audit needs; 90 days is not sufficient for every environment.
Disabling a retention policy is different from stopping flow-log collection. Check both flow-log settings and storage lifecycle or deletion policies to establish how long records actually remain available.
Potential impact
- Evidence of communication during an incident may be missing.
- Long-term traffic comparisons and audit evidence can be incomplete.
Remediation
- Define the required period and apply it through supported
retention_policysettings and storage policies. - Verify collection and the oldest available records, and check for other policies that delete logs earlier. Manage access and cost as well.
- New NSG flow logs cannot be created from June 30, 2025. Migrate existing logs to Virtual Network flow logs before retirement on September 30, 2027, and review retention as part of that migration.
Examples
These excerpts use an older AzureRM format to compare retention for an existing NSG flow log. The name and referenced resources are omitted. They are not examples for creating a new NSG flow log today.
Before
resource "azurerm_network_watcher_flow_log" "example" {
network_watcher_name = azurerm_network_watcher.test.name
resource_group_name = azurerm_resource_group.test.name
network_security_group_id = azurerm_network_security_group.test.id
storage_account_id = azurerm_storage_account.test.id
enabled = true
retention_policy {
enabled = true
days = 89
}
}
An 89-day period is one day short if the organization requires 90 days. This number alone does not establish the actual investigation window.
After
resource "azurerm_network_watcher_flow_log" "example" {
network_watcher_name = azurerm_network_watcher.test.name
resource_group_name = azurerm_resource_group.test.name
network_security_group_id = azurerm_network_security_group.test.id
storage_account_id = azurerm_storage_account.test.id
enabled = true
retention_policy {
enabled = true
days = 90
}
}
The period is increased to the example baseline of 90 days. This does not recover previously deleted logs; verify actual storage and investigation requirements.