Skip to content

This tool is not affiliated with, endorsed by or sponsored by Microsoft Corporation. Azure, Microsoft Azure and Microsoft Defender for Cloud are trademarks of the Microsoft group of companies. Other names are trademarks of their respective owners.

Glossary

NSG and VNet flow logs

Network Watcher logs of IP flows through network security groups or virtual networks: 5-tuple, direction, decision and byte counts, per minute.

Flow logs are Azure Network Watcher records of IP traffic. NSG flow logs cover one network security group; VNet flow logs cover a whole virtual network. Both are written to a storage account at one-minute intervals as tuples: timestamp, source and destination IP and port, protocol, direction, decision or flow state, and — for NSG version 2 and VNet flow logs — packets and bytes.

Microsoft has announced that NSG flow logs retire on September 30, 2027; VNet flow logs replace them. They carry no payloads.

See NSG and VNet flow logs analysis for exfiltration.

This tool is not affiliated with, endorsed by or sponsored by Microsoft Corporation. Azure, Microsoft Azure and Microsoft Defender for Cloud are trademarks of the Microsoft group of companies. Other names are trademarks of their respective owners.