Connection monitors still billing tests after every source VM was deleted
What does ZopNight detect here?
Azure Network Watcher Connection Monitor bills per test per month beyond the first 10, where a test is one source, destination and test configuration combined. ZopNight flags a connection monitor when every source endpoint it tests from has provably been deleted, so it runs nothing, and reports the monitor's full priced cost as the saving.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1403 |
| Category | orphan |
| Severity | medium |
| Metric | none — pure configuration read |
| Threshold | all source endpoints deleted |
| Source | ZopNight |
| Permissions used | Microsoft.Network/networkWatchers/connectionMonitors/read · Microsoft.Compute/virtualMachines/read |
A monitor with no source still counts its tests
Connection Monitor organises checks into test groups of sources, destinations and test configurations, and defines a test as the combination of one source, one destination and one configuration. The Network Watcher pricing page includes the first 10 tests per month and bills every test beyond that per month, for tests created from the portal, PowerShell, CLI or REST.
Sources are the machines that run the checks: Azure VMs, scale sets, or Azure Arc-enabled hosts with the Network Watcher extension. Once those machines are decommissioned, the monitor has nothing to run from, yet its test count and the charge stay in place. This is the usual leftover when a fleet is rebuilt and the monitoring configuration is not.
Listing a monitor’s sources
Connection monitors are regional. List them, then list the endpoints of a suspect monitor and check whether each source resource still exists:
az network watcher connection-monitor list --location <region> -o table
az network watcher connection-monitor endpoint list \ --connection-monitor <monitor> --location <region> -o table
az vm show --ids <source-resource-id> --query name -o tsvA monitor whose portal view shows no recent results is a strong hint as well.
Proving every source is gone
ZopNight works from the monitor’s enabled test groups: the full list of source resource IDs and the number of billed tests. The finding needs all of the following:
- The monitor has at least one billed test.
- Not one of its sources appears in ZopNight’s inventory.
- Each source sits in a subscription ZopNight actually scans, so its absence is meaningful.
- Each source is a type ZopNight would have discovered had it existed: a virtual machine, a scale set, a virtual network or a Log Analytics workspace.
- The monitor has a positive price.
Sources that make the verdict unprovable
Azure Arc machines, subnet endpoints and anything in a subscription ZopNight does not scan cannot be proven deleted, so a monitor using any of them gets no finding. The rule also stays silent when only some sources are gone: those tests still run, and splitting the bill would require knowing which sources pair with which destinations and configurations.
Why the whole cost is recoverable
saving = full monthly cost of the connection monitorcost after fix = 0A test executes from its source. With every source deleted, no test in the monitor can run, so deleting the monitor loses no data you currently receive.
Clearing out the dead monitor
- Open Network Watcher, Connection monitor, and confirm the source endpoints refer to machines that no longer exist.
- If the monitoring is still wanted, add the replacement machines as sources and remove the dead ones instead of deleting.
- Otherwise delete it:
az network watcher connection-monitor delete --location <region> --name <monitor>.