Uredi

Supported logs for Microsoft.Network/azureFirewalls

The following table lists the types of logs available for the Microsoft.Network/azureFirewalls resource type.

For a list of supported metrics, see Supported metrics - Microsoft.Network/azureFirewalls

Category Costs to export Log table Supports basic log plan Supports ingestion-time transformation Example queries
AZFWApplicationRule Yes AZFWApplicationRule

Contains all Application rule log data. Each match between data plane and Application rule creates a log entry with the data plane packet and the matched rule's attributes.

Yes Yes Queries
AZFWApplicationRuleAggregation Yes AZFWApplicationRuleAggregation

Contains aggregated Application rule log data for Policy Analytics.

Yes Yes
AZFWDnsAdditional Yes AZFWDnsFlowTrace

Contains all the DNS proxy data between the client, firewall, and DNS server.

Yes No
AZFWDnsQuery Yes AZFWDnsQuery

Contains all DNS Proxy events log data.

Yes Yes Queries
AZFWFatFlow Yes AZFWFatFlow

This query returns the top flows across Azure Firewall instances. Log contains flow information, date transmission rate (in Megabits per second units) and the time period when the flows were recorded. Please follow the documentation to enable Top flow logging and details on how it is recorded.

Yes Yes Queries
AZFWFlowTrace Yes AZFWFlowTrace

Flow logs across Azure Firewall instances. Log contains flow information, flags and the time period when the flows were recorded. Please follow the documentation to enable flow trace logging and details on how it is recorded.

Yes Yes Queries
AZFWFqdnResolveFailure Yes No No
AZFWIdpsSignature Yes AZFWIdpsSignature

Contains all data plane packets that were matched with one or more IDPS signatures.

Yes Yes Queries
AZFWNatRule Yes AZFWNatRule

Contains all DNAT (Destination Network Address Translation) events log data. Each match between data plane and DNAT rule creates a log entry with the data plane packet and the matched rule's attributes.

Yes Yes Queries
AZFWNatRuleAggregation Yes AZFWNatRuleAggregation

Contains aggregated NAT Rule log data for Policy Analytics.

Yes Yes
AZFWNetworkRule Yes AZFWNetworkRule

Contains all Network Rule log data. Each match between data plane and network rule creates a log entry with the data plane packet and the matched rule's attributes.

Yes Yes Queries
AZFWNetworkRuleAggregation Yes AZFWNetworkRuleAggregation

Contains aggregated Network rule log data for Policy Analytics.

Yes Yes
AZFWThreatIntel Yes AZFWThreatIntel

Contains all Threat Intelligence events.

Yes Yes Queries
AzureFirewallApplicationRule No AzureDiagnostics

Logs from multiple Azure resources.

No No Queries
AzureFirewallDnsProxy No AzureDiagnostics

Logs from multiple Azure resources.

No No Queries
AzureFirewallNetworkRule No AzureDiagnostics

Logs from multiple Azure resources.

No No Queries

Next Steps