Azure FW Policy Analytics (preview)

Belan Marek 51 Reputation points
2022-10-12T12:53:11.193+00:00

We have zero matching flow and hit counts on Firewall Policy Analytics (preview).
Traffic is going through FW.
All log is going to log analytics created by FW.

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
656 questions
{count} votes

1 answer

Sort by: Most helpful
  1. GitaraniSharma-MSFT 49,486 Reputation points Microsoft Employee
    2022-10-17T15:45:52.303+00:00

    Hello @Belan Marek ,

    Welcome to Microsoft Q&A Platform. Thank you for reaching out & hope you are doing well.

    I understand that you enabled Azure Firewall Policy Analytics and the traffic is going through the Firewall and the logs are going to the configured log analytics but you have zero matching flow and hit counts.

    Could you please confirm if all the prerequisites are met?
    Refer : https://video2.skills-academy.com/en-us/azure/firewall/firewall-preview#prerequisites

    The network rule name logging preview feature must be enabled to view network rules analysis.
    Refer : https://video2.skills-academy.com/en-us/azure/firewall/firewall-preview#network-rule-name-logging-preview

    The structured firewall logs feature must be enabled on Firewall Standard or Premium.
    Refer : https://video2.skills-academy.com/en-us/azure/firewall/firewall-preview#structured-firewall-logs-preview

    NOTE : Policy Analytics has a dependency on both Log Analytics and Azure Firewall resource specific logging.
    You can check logs are configured appropriately by running a log analytics query on the resource specific tables such as AZFWNetworkRuleAggregation, AZFWApplicationRuleAggregation, and AZFWNatRuleAggregation.

    Kindly let us know if the above helps or you need further assistance on this issue.

    ----------------------------------------------------------------------------------------------------------------

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.