Bilješka
Pristup ovoj stranici zahtijeva provjeru vjerodostojnosti. Možete pokušati da se prijavite ili promijenite direktorije.
Pristup ovoj stranici zahtijeva provjeru vjerodostojnosti. Možete pokušati promijeniti direktorije.
The following table lists the types of logs available for the Microsoft.Network/azureFirewalls resource type.
For a list of supported metrics, see Supported metrics - Microsoft.Network/azureFirewalls
| Category | Costs to export | Log table | Supports basic log plan | Supports ingestion-time transformation | Example queries |
|---|---|---|---|---|---|
| AZFWApplicationRule | Yes | AZFWApplicationRule Contains all Application rule log data. Each match between data plane and Application rule creates a log entry with the data plane packet and the matched rule's attributes. |
Yes | Yes | Queries |
| AZFWApplicationRuleAggregation | Yes | AZFWApplicationRuleAggregation Contains aggregated Application rule log data for Policy Analytics. |
Yes | Yes | |
| AZFWDnsAdditional | Yes | AZFWDnsFlowTrace Contains all the DNS proxy data between the client, firewall, and DNS server. |
Yes | No | |
| AZFWDnsQuery | Yes | AZFWDnsQuery Contains all DNS Proxy events log data. |
Yes | Yes | Queries |
| AZFWFatFlow | Yes | AZFWFatFlow This query returns the top flows across Azure Firewall instances. Log contains flow information, date transmission rate (in Megabits per second units) and the time period when the flows were recorded. Please follow the documentation to enable Top flow logging and details on how it is recorded. |
Yes | Yes | Queries |
| AZFWFlowTrace | Yes | AZFWFlowTrace Flow logs across Azure Firewall instances. Log contains flow information, flags and the time period when the flows were recorded. Please follow the documentation to enable flow trace logging and details on how it is recorded. |
Yes | Yes | Queries |
| AZFWFqdnResolveFailure | Yes | No | No | ||
| AZFWIdpsSignature | Yes | AZFWIdpsSignature Contains all data plane packets that were matched with one or more IDPS signatures. |
Yes | Yes | Queries |
| AZFWNatRule | Yes | AZFWNatRule Contains all DNAT (Destination Network Address Translation) events log data. Each match between data plane and DNAT rule creates a log entry with the data plane packet and the matched rule's attributes. |
Yes | Yes | Queries |
| AZFWNatRuleAggregation | Yes | AZFWNatRuleAggregation Contains aggregated NAT Rule log data for Policy Analytics. |
Yes | Yes | |
| AZFWNetworkRule | Yes | AZFWNetworkRule Contains all Network Rule log data. Each match between data plane and network rule creates a log entry with the data plane packet and the matched rule's attributes. |
Yes | Yes | Queries |
| AZFWNetworkRuleAggregation | Yes | AZFWNetworkRuleAggregation Contains aggregated Network rule log data for Policy Analytics. |
Yes | Yes | |
| AZFWThreatIntel | Yes | AZFWThreatIntel Contains all Threat Intelligence events. |
Yes | Yes | Queries |
| AzureFirewallApplicationRule | No | AzureDiagnostics Logs from multiple Azure resources. |
No | No | Queries |
| AzureFirewallDnsProxy | No | AzureDiagnostics Logs from multiple Azure resources. |
No | No | Queries |
| AzureFirewallNetworkRule | No | AzureDiagnostics Logs from multiple Azure resources. |
No | No | Queries |
Next Steps
- Learn more about resource logs
- Stream resource logs to Event Hubs
- Change resource log diagnostic settings using the Azure Monitor REST API
- Analyze logs from Azure storage with Log Analytics
- Optimize log queries in Azure Monitor
- Aggregate data in a Log Analytics workspace by using summary rules (Preview)