| name | cis-azure-foundations-6.1.1.7 |
| description | Ensure virtual network flow logs are captured and sent to Log Analytics |
| category | cis-azure-foundations |
| version | 5.0.0 |
| author | cyberstrike-official |
| tags | ["cis","azure","logging","monitoring","vnet","flow-logs","network"] |
| cis_id | 6.1.1.7 |
| cis_benchmark | CIS Microsoft Azure Foundations Benchmark v5.0.0 |
| tech_stack | ["azure"] |
| cwe_ids | [] |
| chains_with | ["cis-azure-foundations-6.1.1.5"] |
| prerequisites | [] |
| severity_boost | {} |
Ensure that virtual network flow logs are captured and sent to Log Analytics
Description
Ensure that virtual network flow logs are captured and fed into a central log analytics workspace.
Rationale
Virtual network flow logs provide critical visibility into traffic patterns. Sending logs to a Log Analytics workspace enables centralized analysis, correlation, and alerting for faster threat detection and response.
Impact
- Virtual network flow logs are charged per gigabyte of network flow logs collected and come with a free tier of 5 GB/month per subscription.
- If traffic analytics is enabled with virtual network flow logs, traffic analytics pricing applies at per gigabyte processing rates.
- The storage of logs is charged separately.
Audit Procedure
Using Azure Portal
- Go to
Network Watcher.
- Under
Logs, select Flow logs.
- Click
Add filter.
- From the
Filter drop-down menu, select Flow log type.
- From the
Value drop-down menu, check Virtual network only.
- Click
Apply.
- Ensure that at least one virtual network flow log is listed and is configured to send logs to a
Log Analytics Workspace.
Expected Result
At least one virtual network flow log should exist and be configured to send logs to a Log Analytics Workspace with traffic analytics enabled.
Remediation
Remediate from Azure Portal
- Go to
Network Watcher.
- Under
Logs, click Flow logs.
- Click
+ Create.
- Select a subscription.
- Next to
Flow log type, select Virtual network.
- Click
+ Select target resource.
- Select
Virtual network.
- Select a virtual network.
- Click
Confirm selection.
- Select a storage account, or create a new storage account.
- Set the retention in days for the storage account.
- Click
Next.
- Under
Analytics, for Flow logs version, select .