Flow logs sending data to Traffic Analytics every 10 minutes instead of every 60
What does ZopNight detect here?
ZopNight flags an Azure Network Watcher flow log that has Traffic Analytics enabled with a processing interval of exactly 10 minutes. The Azure price list charges $3.50 per GB processed at that interval against $2.30 at 60 minutes, so ZopNight estimates the saving as 30% of the flow log's total billed cost.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1399 |
| Category | rightsizing |
| Severity | medium |
| Metric | none — pure configuration read |
| Threshold | trafficAnalyticsInterval = 10 |
| Source | ZopNight |
| Permissions used | Microsoft.Network/networkWatchers/read · Microsoft.Network/networkWatchers/flowLogs/read |
Paying the accelerated processing rate for hourly questions
Traffic Analytics processes flow log data in Log Analytics and bills per gigabyte processed, with no free tier. The flow log CLI reference lists 10 and 60 minutes as the allowed processing intervals. The Network Watcher pricing page calls the 10-minute option accelerated processing. In the Azure retail price list for East US, flow log collection is $0.50 per GB after 5 free GB a month, Traffic Analytics processing is $2.30 per GB at 60 minutes, and $3.50 per GB at 10 minutes.
Most Traffic Analytics use is capacity planning, cost attribution and after-the-fact security review. None of those need data ten minutes fresh, yet the faster interval raises the processing charge on every gigabyte by more than half.
Finding flow logs on the 10-minute interval
Flow logs are listed per region:
az network watcher flow-log list --location eastus \ --query "[].{name:name, enabled:enabled, ta:flowAnalyticsConfiguration.networkWatcherFlowAnalyticsConfiguration.enabled, interval:flowAnalyticsConfiguration.networkWatcherFlowAnalyticsConfiguration.trafficAnalyticsInterval}" \ -o tableRepeat for each region where you have flow logs, and look for an interval of 10.
Three settings ZopNight reads on each flow log
- The flow log itself is enabled.
- Traffic Analytics is enabled on it.
- The processing interval is exactly 10 minutes.
The flow log must also have a billed monthly cost in ZopNight’s cost data.
Flow logs this rule ignores
A flow log on the 60-minute interval is already on the cheaper rate. Azure documents only 10 and 60, so any other value is treated as unknown and not priced. Disabled flow logs, flow logs without Traffic Analytics, and flow logs with no billed cost produce no finding.
Why the saving is 30% of the whole flow-log bill
The flow log’s cost includes both collection and Traffic Analytics processing, and both are charged on the same gigabytes. Only the processing rate changes, so the saving is the rate difference over the combined per-GB rate:
saving = flow log monthly cost x (3.50 - 2.30) / (0.50 + 3.50) = flow log monthly cost x 0.30At 100 GB a month that is $50 of collection plus $350 of processing, $400 in all, and moving to 60 minutes saves $120. Applying the processing-only ratio to the full $400 would overstate it. The 5 free GB make real collection slightly cheaper, which means this figure errs a little low.
Moving Traffic Analytics to hourly processing
- Check with the people who use the Traffic Analytics workbooks that hourly data is enough.
- In the portal, open Network Watcher, then Flow logs, select the flow log, and set the Traffic Analytics processing interval to every 60 minutes.
- Or from the CLI:
az network watcher flow-log update --location eastus --resource-group my-rg --name my-flow-log --interval 60. - Confirm the new interval with the list command above.