Azure Firewall Policy Analytics

Handian Sudianto 4,981 Reputation points
2024-08-19T07:53:46.7133333+00:00

Hello,

I create some rule in the azure firewall, but why on the policy analytics seem all my rule is not hitting? Matching flows and hit count always 0? The rule mainly is to block and permit access to the internet. The rule is working normally and the hit counts should be increased.

User's image User's image

We can see on the firewall metric the traffic hitting the rules.

User's image

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
671 questions
0 comments No comments
{count} votes

Accepted answer
  1. KapilAnanth-MSFT 46,096 Reputation points Microsoft Employee
    2024-08-19T09:26:05.26+00:00

    @Handian Sudianto ,

    Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.

    Can you confirm you have enabled Policy Analytics explicitly,

    1. Select Policy analytics in the table of contents and select "Insights"
    2. Next, select Configure Workspaces.
    3. In the pane that opens, select the Enable Policy Analytics checkbox.
    4. Next, choose a log analytics workspace. The log analytics workspace should be the same workspace configured in the firewall Diagnostic settings.
    5. Select Save after you choose the log analytics workspace.

    Also, note that logs take 60 minutes to appear after enabling them for the first time. This is because logs are aggregated in the backend every hour

    Cheers,

    Kapil


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.