Can we Ingest Flow logs from VNet in Azure?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Can we Ingest Flow logs from VNet in Azure?

L1 Bithead

I got a use case were user has enabled flow logs in Azure on Vnet level but Prisma Cloud ingest data from network watcher from NSG flow log right? can we have any way or method in Prisma Cloud to ingest data from VNet directly? 

 

Prisma Cloud 

3 accepted solutions

Accepted Solutions

L2 Linker

Prisma Cloud ingests network traffic data from Azure through Network Security Group (NSG) flow logs, a feature of Azure Network Watcher. It does not directly ingest Azure VNet flow logs. To enable this, you must configure NSG flow logs to send data to a storage account, and then ensure Prisma Cloud has the necessary permissions to access that storage account.

 

Here is a checklist on what to verify when configuring network flow logs:

https://docs.prismacloud.io/en/enterprise-edition/content-collections/connect/connect-cloud-accounts...

 

Here is a list of our supported resources for flow logs:

https://docs.prismacloud.io/en/enterprise-edition/content-collections/search-and-investigate/network...

View solution in original post

Thanks for reply. That means there is no way to do something in Prisma cloud to ingest flow logs from VNet instead of NSG right?

View solution in original post

That is correct, as of currently we do not support VNet flow logs ingestion but it is in the pipeline for future enhancements. 

 

Please monitor our new releases notes. 

https://docs.prismacloud.io/en/enterprise-edition/rn/look-ahead-planned-updates-prisma-cloud/look-ah...

 

Especially given the announcement from Microsoft "Network security group flow logs in Azure Network Watcher will be retired on 30 September 2027.As part of this retirement, you'll no longer be able to create new NSG flow logs starting 30 June 2025."

source: https://learn.microsoft.com/en-us/azure/network-watcher/vnet-flow-logs-overview

View solution in original post

3 REPLIES 3

L2 Linker

Prisma Cloud ingests network traffic data from Azure through Network Security Group (NSG) flow logs, a feature of Azure Network Watcher. It does not directly ingest Azure VNet flow logs. To enable this, you must configure NSG flow logs to send data to a storage account, and then ensure Prisma Cloud has the necessary permissions to access that storage account.

 

Here is a checklist on what to verify when configuring network flow logs:

https://docs.prismacloud.io/en/enterprise-edition/content-collections/connect/connect-cloud-accounts...

 

Here is a list of our supported resources for flow logs:

https://docs.prismacloud.io/en/enterprise-edition/content-collections/search-and-investigate/network...

Thanks for reply. That means there is no way to do something in Prisma cloud to ingest flow logs from VNet instead of NSG right?

That is correct, as of currently we do not support VNet flow logs ingestion but it is in the pipeline for future enhancements. 

 

Please monitor our new releases notes. 

https://docs.prismacloud.io/en/enterprise-edition/rn/look-ahead-planned-updates-prisma-cloud/look-ah...

 

Especially given the announcement from Microsoft "Network security group flow logs in Azure Network Watcher will be retired on 30 September 2027.As part of this retirement, you'll no longer be able to create new NSG flow logs starting 30 June 2025."

source: https://learn.microsoft.com/en-us/azure/network-watcher/vnet-flow-logs-overview

  • 3 accepted solutions
  • 214 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!