# Azure Connection Monitor With No Surviving Source

> Flags Azure connection monitors whose every source endpoint has been deleted, so they bill for tests that can never run.

Source: https://zop.dev/integrations/azure/recommendations/azure-connection-monitor-with-no-surviving-source

---

## A monitor with no source still counts its tests

[Connection Monitor](https://learn.microsoft.com/en-us/azure/network-watcher/connection-monitor-overview)
organises checks into test groups of sources, destinations and test configurations, and defines a
test as the combination of one source, one destination and one configuration. The
[Network Watcher pricing page](https://azure.microsoft.com/en-us/pricing/details/network-watcher/)
includes the first 10 tests per month and bills every test beyond that per month, for tests created
from the portal, PowerShell, CLI or REST.

Sources are the machines that run the checks: Azure VMs, scale sets, or Azure Arc-enabled hosts
with the Network Watcher extension. Once those machines are decommissioned, the monitor has nothing
to run from, yet its test count and the charge stay in place. This is the usual leftover when a
fleet is rebuilt and the monitoring configuration is not.

## Listing a monitor's sources

Connection monitors are regional. List them, then list the endpoints of a suspect monitor and check
whether each source resource still exists:

```bash
az network watcher connection-monitor list --location <region> -o table

az network watcher connection-monitor endpoint list \
  --connection-monitor <monitor> --location <region> -o table

az vm show --ids <source-resource-id> --query name -o tsv
```

A monitor whose portal view shows no recent results is a strong hint as well.

## Proving every source is gone

ZopNight works from the monitor's enabled test groups: the full list of source resource IDs and the
number of billed tests. The finding needs all of the following:

1. The monitor has at least one billed test.
2. Not one of its sources appears in ZopNight's inventory.
3. Each source sits in a subscription ZopNight actually scans, so its absence is meaningful.
4. Each source is a type ZopNight would have discovered had it existed: a virtual machine, a scale
   set, a virtual network or a Log Analytics workspace.
5. The monitor has a positive price.

## Sources that make the verdict unprovable

Azure Arc machines, subnet endpoints and anything in a subscription ZopNight does not scan cannot be
proven deleted, so a monitor using any of them gets no finding. The rule also stays silent when only
some sources are gone: those tests still run, and splitting the bill would require knowing which
sources pair with which destinations and configurations.

## Why the whole cost is recoverable

```text
saving = full monthly cost of the connection monitor
cost after fix = 0
```

A test executes from its source. With every source deleted, no test in the monitor can run, so
deleting the monitor loses no data you currently receive.

## Clearing out the dead monitor

1. Open Network Watcher, Connection monitor, and confirm the source endpoints refer to machines that
   no longer exist.
2. If the monitoring is still wanted, add the replacement machines as sources and remove the dead
   ones instead of deleting.
3. Otherwise delete it:
   `az network watcher connection-monitor delete --location <region> --name <monitor>`.
