Skip to main content

Network Watcher

Azure Network Watcher is the regional service for network diagnostics and flow logging. The Azure Enterprise Baseline creates it in every subscription and records a VNet flow log for every virtual network of the landing zone into the immutable audit storage.

What it does​

Network Watcher is one resource per subscription and region. It provides diagnostics (connection troubleshooting, next-hop and IP flow checks, packet capture) and VNet flow logs: records of every IP flow through a virtual network, with source, destination, ports, protocol, whether the flow was allowed or denied, and byte and packet counts. Flow logs are written to a storage account. Traffic Analytics processes them on a schedule into a Log Analytics workspace, where they can be queried and visualized, and bills for that ingestion.

How BuiltForProd uses it​

One watcher per subscription. The subscription baseline creates NetworkWatcher_eastus2 in the resource group NetworkWatcherRG, with Azure's conventional names, in all 14 subscriptions. It exists before any virtual network does, so Azure never creates one of its own.

Flow logs on every network. modules/virtual-network adds a VNet flow log (version 2) to each network it builds: the hub, each stage spoke and the runner network. The flow log resource belongs to the watcher of the network's own subscription; its destination is the regional audit storage account stacmeeus2auditlogs in acme-core-audit.

SettingValue
ScopeThe whole virtual network, every subnet
DestinationThe audit storage of the region, in acme-core-audit
RetentionGoverned by the audit storage itself: 365-day WORM retention, cool after 90 days, archive after 365
Retention on the flow log0 (none), so the flow log does not add a lifecycle rule that would override the account's own
Traffic Analyticsenable_traffic_analytics in network.hcl, off; when on, every 10 minutes into the audit workspace

Keeping retention on the audit storage rather than on each flow log means one policy governs every record: write once, kept for a year, then tiered down. During the retention period no flow record can be changed or deleted, even by an Owner, and the audit-protection policy initiative denies deleting the account itself.

With Traffic Analytics off, the flow logs are evidence and an investigation source, read straight from storage. Switching it on sends the processed flows to the audit Log Analytics workspace in acme-core-audit, where they can be queried with KQL alongside the Activity Log, at the cost of the extra ingestion. The firewall's own logs and the NSG event logs already reach that workspace either way.

Terms you will see​

TermMeaning
Network WatcherThe per-subscription, per-region network diagnostics resource.
VNet flow logA record of every IP flow through a virtual network, written to storage.
Traffic AnalyticsProcessing of flow logs into a Log Analytics workspace; off by default here.
WORM retentionWrite once, read many: blobs cannot be changed or deleted during the period.
NetworkWatcherRGThe conventional resource group of the watcher in each subscription.

Where to read more​