Skip to main content
orphan · azure

NSG flow logs that duplicate an unfiltered virtual network flow log

rule IDs covered
1
severity
high

What does ZopNight detect here?

Azure bills flow log collection per GB, so recording the same packets twice means paying twice. ZopNight flags an enabled NSG flow log when every virtual network its NSG governs is already covered by an unfiltered VNet flow log and the NSG has no NIC binding, then reports the NSG flow log's full cost as the saving.

Signal and threshold

How ZopNight evaluates NSG flow logs that duplicate an unfiltered virtual network flow log.
Field Value
Rule IDsRC-1400
Categoryorphan
Severityhigh
Metricnone — pure configuration read
Thresholdevery governed VNet covered by an unfiltered VNet flow log
SourceZopNight
Permissions usedMicrosoft.Network/networkWatchers/flowLogs/read · Microsoft.Network/networkSecurityGroups/read

Paying twice for the same packets

Network Watcher has two flow logging models. NSG flow logs attach to a network security group; virtual network flow logs attach to a whole network, subnet or NIC. Microsoft’s VNet flow logs overview recommends disabling NSG flow logs before enabling VNet flow logs on the same workloads, to avoid duplicate traffic recording and additional costs. Both kinds are billed per GB collected after the first 5 GB each month, per the Network Watcher pricing page, and traffic analytics adds a per-GB processing charge on top.

NSG flow logs are also on their way out: Microsoft retires them on September 30, 2027 and no longer allows new ones to be created. An NSG log left running beside a newer VNet log is pure overlap.

Finding overlapping logs

List the flow logs in a region with their targets. NSG logs point at a networkSecurityGroups resource; VNet logs point at a virtualNetworks resource:

Terminal window
az network watcher flow-log list --location <region> \
--query "[].{name:name, enabled:enabled, target:targetResourceId}" -o table
az network nsg show --resource-group <rg> --name <nsg> \
--query "{subnets:subnets[].id, nics:networkInterfaces[].id}"

If every subnet the NSG protects lives in a network that already has an enabled VNet flow log, the NSG log is redundant.

Three proofs before recommending a deletion

  • Every network is covered. An NSG can protect subnets in more than one virtual network. Each one must have its own enabled VNet flow log; covering the first is not enough.
  • The covering log is unfiltered. VNet flow logs can take filtering criteria that record only matching flows. A filtered log is not full coverage, and a log whose filter state is unknown does not count either.
  • No NIC binding. If the NSG is attached to a network interface as well as subnets, that traffic is not accounted for by the network-level match, and the finding is withheld.

The NSG flow log itself must be enabled and must have a positive price.

Cases left alone

A disabled NSG flow log, an NSG with no known networks, or any coverage gap on a single network produces no finding. The goal is to never recommend deleting the only record of some traffic. Gateway subnet logs are a separate case, covered by Azure Flow Log on a Gateway Subnet.

The NSG flow log cost that disappears

Terminal window
saving = full monthly cost of the redundant NSG flow log
cost after fix = 0

Deleting the duplicate stops its collection, storage and analytics meters together.

Retiring the duplicate NSG flow log

  1. Confirm the covering VNet flow log is healthy and its data is arriving in the destination storage account.
  2. If traffic analytics ran on the NSG flow log, enable it on the VNet flow log too.
  3. Delete the NSG flow log: az network watcher flow-log delete --location <region> --name <flow-log>.
  4. Check for further NSG logs on the same workloads; one can exist at both the subnet and the NIC level.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·