Deploy Network Watcher in all regions where you have networking services
Impact:LowCategory:Monitoring and Alerting
APRL GUID:4e133bd0-8762-bc40-a95b-b29142427d73
Description:
Azure Network Watcher offers tools for monitoring, diagnosing, viewing metrics, and managing logs for IaaS resources. It helps maintain the health of VMs, VNets, application gateways, load balancers, but not for PaaS or Web analytics.
Potential Benefits:
Enhanced monitoring and diagnostics for Azure IaaS
Click the Azure Resource Graph tab to view the query
//under-development
Fix Flow Log configurations in Failed state or Disabled Status
Impact:LowCategory:Monitoring and Alerting
APRL GUID:22a769ed-0ecb-8b49-bafe-8f52e6373d9c
Description:
Network security group flow logging is a feature of Azure Network Watcher that logs IP traffic info through a network security group. If in Failed state, monitoring data from the associated resource is not collected.
Click the Azure Resource Graph tab to view the query
//AzureResourceGraphQuery//ThisquerywillreturnallFlowLogswhereFlowAnalyticsConfigurationisdisabledresources|wheretype=~"microsoft.network/networkwatchers/flowlogs"|whereproperties.targetResourceIdcontains"microsoft.network/virtualNetworks"|wherenot(properties.flowAnalyticsConfiguration.networkWatcherFlowAnalyticsConfiguration.enabled)|projectrecommendationId="bf0b7dbd-016d-458c-af99-70fcb03ad451",name,id,tags,param1="Flow Analytics Configuration is disabled",param2=strcat("Vnet Name : ",properties.targetResourceId)