View real time firewall logs?

Goofoff 91 Reputation points
2020-10-02T04:19:57.163+00:00

what is the easiest way and/or best viewer to watch your real time network traffic through azure firewall and/or NSG's
Log analytics/event hub? any way to just watch the traffic the way you would on a normal firewall with a connection monitor or at least.
the ops manager here hates doing log analytics queries.

Just wondering if anyone had some tools / workflows to give some people who are dislike doing queries for everything.

Thank you

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
564 questions
Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,137 questions
0 comments No comments
{count} votes

Accepted answer
  1. suvasara-MSFT 10,001 Reputation points
    2020-10-02T06:55:37.787+00:00

    @Goofoff , the feature you are looking for is available in AppService named "Log Stream". This is not yet available for Azure Firewall.

    29828-image.png

    There are two more options that should work with this feature request depending on your workflow. If you are looking for application health centric metrics with inflow and outflow live traffic with minimum latency ~1 sec, then we have application insights "Live Metrics".

    Else, we have "Azure firewall workbook" which can gain insights into Azure Firewall events, learn about your application and network rules, and see statistics for firewall activities across URLs, ports, and addresses. Azure Firewall Workbook allows you to filter your firewalls and resource groups, and dynamically filter per category with easy to read data sets when investigating an issue in your logs.

    If none of the solution works for your scenario then please feel to raise a feature request here in this feedback section. I recommend you to upvote it and other features that are of interest. In general, Azure feature team would check feasibility of a feature request, triage it, prioritize against existing feature backlog, add in roadmap as appropriate and would announce and/or update the related Azure document once a feature request is addressed.

    ----------

    Please do not forget to "Accept the answer" wherever the information provided helps you to help others in the community.

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Goofoff 91 Reputation points
    2020-10-04T22:07:09.53+00:00

    I think the Azure Firewall Workbook will fill in for what i need for now until log stream is enabled for firewall.
    Thank you.

    0 comments No comments