How to use Log Analytics Workspace with UI while accepting public networks

EXT Smith Mathilda 1 Reputation point
2021-09-16T11:32:52.42+00:00

132713-screenshot-2021-09-16-at-142809.png

I would like to be able to choose NO in this option, but it does not allow me to do so. Any suggestions on how I can allow public networks for my Log Analytics Workspace through UI?

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
2,803 questions
Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,142 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Andriy Bilous 10,901 Reputation points MVP
    2021-09-16T12:00:01.703+00:00

    Hello @EXT Smith Mathilda

    The settings you mentioned, control access from public networks, meaning networks not connected to the listed scopes (AMPLSs).
    132668-image.png

    In your resource's menu, there's a menu item called Network Isolation on the left-hand side. This page controls both which networks can reach the resource through a Private Link, and whether other networks can reach it or not.
    Connecting to scopes (AMPLSs) allows traffic from the virtual network connected to each AMPLS to reach the resource.

    The settings on the bottom part of this page control access from public networks, meaning networks not connected to the listed scopes (AMPLSs).

    If you set Allow public network access for ingestion to No, then clients (machines, SDKs, etc.) outside of the connected scopes can't upload data or send logs to the resource.

    If you set Allow public network access for queries to No, then clients (machines, SDKs etc.) outside of the connected scopes can't query data in the resource. That data includes access to logs, metrics, and the live metrics stream, as well as experiences built on top such as workbooks, dashboards, query API-based client experiences, insights in the Azure portal, and more. Experiences running outside the Azure portal and that query Log Analytics data also have to be running within the private-linked VNET.

    ****Starting September, 2021, Network Isolation will be strictly enforced. Resources set to block queries from public networks, and that aren't connected to any private network (through an AMPLS) will stop accepting queries from any network.****

    https://learn.microsoft.com/en-us/azure/azure-monitor/logs/private-link-configure

    0 comments No comments