Network Watcher
Azure Network Watcher is the regional service for network diagnostics and flow logging. The Azure Enterprise Baseline creates it in every subscription and records a VNet flow log for every virtual network of the landing zone into the immutable audit storage.
What it does
Network Watcher is one resource per subscription and region. It provides diagnostics (connection troubleshooting, next-hop and IP flow checks, packet capture) and VNet flow logs: records of every IP flow through a virtual network, with source, destination, ports, protocol, whether the flow was allowed or denied, and byte and packet counts. Flow logs are written to a storage account. Traffic Analytics processes them on a schedule into a Log Analytics workspace, where they can be queried and visualized, and bills for that ingestion.
How BuiltForProd uses it
One watcher per subscription. The subscription baseline creates NetworkWatcher_eastus2 in the resource group NetworkWatcherRG, with Azure's conventional names, in all 14 subscriptions. It exists before any virtual network does, so Azure never creates one of its own.
Flow logs on every network. modules/virtual-network adds a VNet flow log (version 2) to each network it builds: the hub, each stage spoke and the runner network. The flow log resource belongs to the watcher of the network's own subscription; its destination is the regional audit storage account stacmeeus2auditlogs in acme-core-audit.
| Setting | Value |
|---|---|
| Scope | The whole virtual network, every subnet |
| Destination | The audit storage of the region, in acme-core-audit |
| Retention | Governed by the audit storage itself: 365-day WORM retention, cool after 90 days, archive after 365 |
| Retention on the flow log | 0 (none), so the flow log does not add a lifecycle rule that would override the account's own |
| Traffic Analytics | enable_traffic_analytics in network.hcl, off; when on, every 10 minutes into the audit workspace |
Keeping retention on the audit storage rather than on each flow log means one policy governs every record: write once, kept for a year, then tiered down. During the retention period no flow record can be changed or deleted, even by an Owner, and the audit-protection policy initiative denies deleting the account itself.
With Traffic Analytics off, the flow logs are evidence and an investigation source, read straight from storage. Switching it on sends the processed flows to the audit Log Analytics workspace in acme-core-audit, where they can be queried with KQL alongside the Activity Log, at the cost of the extra ingestion. The firewall's own logs and the NSG event logs already reach that workspace either way.
Terms you will see
| Term | Meaning |
|---|---|
| Network Watcher | The per-subscription, per-region network diagnostics resource. |
| VNet flow log | A record of every IP flow through a virtual network, written to storage. |
| Traffic Analytics | Processing of flow logs into a Log Analytics workspace; off by default here. |
| WORM retention | Write once, read many: blobs cannot be changed or deleted during the period. |
NetworkWatcherRG | The conventional resource group of the watcher in each subscription. |
Where to read more
- Azure Enterprise Baseline overview for the audit subscription and its evidence.
- Virtual Network for the networks that are logged.
- Observable for what the platform records and why.