FlowType MaliciousFlow

Steve Platti 41 Reputation points
2021-11-30T13:36:12.967+00:00

Hello -

All of a sudden I am no longer receiving any FlowType of MaliciousFlow. I have made no changes and was regularly receiving a fair amount spread across NSGs. Has there been a change on how MS determines MaliciousFlow traffic? I am still getting large amounts of other FlowTypes.

Any help is appreciated.
Steve

AzureNetworkAnalytics_CL
| where SubType_s == 'FlowLog' and FASchemaVersion_s == '2'
| where FlowType_s =="MaliciousFlow"

Azure Network Watcher
Azure Network Watcher
An Azure service that is used to monitor, diagnose, and gain insights into network performance and health.
169 questions
0 comments No comments
{count} votes

Accepted answer
  1. SaiKishor-MSFT 17,231 Reputation points
    2021-12-02T11:48:33.493+00:00

    @Steve Platti Thank you for reaching out to Microsoft Q&A. I understand that you were having issues with Flowtype MaliciousFlow not showing up in your Network Watcher logs suddenly.

    We recently had an issue due to which the Malicious traffic flowtype was not showing up. A fix was deployed for the same. Therefore, these logs should start showing up soon. Please let us know otherwise.

    Hope this helps. Please let us know if you have any further questions and we will be glad to assist you further. Thank you!

    Remember:

    Please accept an answer if correct. Original posters help the community find answers faster by identifying the correct answer. Here is how.

    Want a reminder to come back and check responses? Here is how to subscribe to a notification.

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Steve Platti 41 Reputation points
    2021-12-02T13:02:37.27+00:00

    I have confirmed the Malicious traffic flowtype is appearing again. Thank you

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.