# Azure Traffic Analytics on the 10-Minute Interval

> Flags flow logs using the 10-minute Traffic Analytics interval and estimates the saving from moving to 60 minutes.

Source: https://zop.dev/integrations/azure/recommendations/azure-traffic-analytics-on-the-10-minute-interval

---

## Paying the accelerated processing rate for hourly questions

Traffic Analytics processes flow log data in Log Analytics and bills per gigabyte processed, with no
free tier. The [flow log CLI reference](https://learn.microsoft.com/en-us/cli/azure/network/watcher/flow-log)
lists 10 and 60 minutes as the allowed processing intervals. The
[Network Watcher pricing page](https://azure.microsoft.com/en-us/pricing/details/network-watcher/)
calls the 10-minute option accelerated processing. In the Azure retail price list for East US, flow
log collection is $0.50 per GB after 5 free GB a month, Traffic Analytics processing is $2.30 per GB
at 60 minutes, and $3.50 per GB at 10 minutes.

Most Traffic Analytics use is capacity planning, cost attribution and after-the-fact security review.
None of those need data ten minutes fresh, yet the faster interval raises the processing charge on
every gigabyte by more than half.

## Finding flow logs on the 10-minute interval

Flow logs are listed per region:

```bash
az network watcher flow-log list --location eastus \
  --query "[].{name:name, enabled:enabled, ta:flowAnalyticsConfiguration.networkWatcherFlowAnalyticsConfiguration.enabled, interval:flowAnalyticsConfiguration.networkWatcherFlowAnalyticsConfiguration.trafficAnalyticsInterval}" \
  -o table
```

Repeat for each region where you have flow logs, and look for an interval of 10.

## Three settings ZopNight reads on each flow log

1. The flow log itself is enabled.
2. Traffic Analytics is enabled on it.
3. The processing interval is exactly 10 minutes.

The flow log must also have a billed monthly cost in ZopNight's cost data.

## Flow logs this rule ignores

A flow log on the 60-minute interval is already on the cheaper rate. Azure documents only 10 and
60, so any other value is treated as unknown and not priced. Disabled flow logs, flow logs without
Traffic Analytics, and flow logs with no billed cost produce no finding.

## Why the saving is 30% of the whole flow-log bill

The flow log's cost includes both collection and Traffic Analytics processing, and both are charged
on the same gigabytes. Only the processing rate changes, so the saving is the rate difference over
the combined per-GB rate:

```text
saving = flow log monthly cost x (3.50 - 2.30) / (0.50 + 3.50)
       = flow log monthly cost x 0.30
```

At 100 GB a month that is $50 of collection plus $350 of processing, $400 in all, and moving to 60
minutes saves $120. Applying the processing-only ratio to the full $400 would overstate it. The 5
free GB make real collection slightly cheaper, which means this figure errs a little low.

## Moving Traffic Analytics to hourly processing

1. Check with the people who use the Traffic Analytics workbooks that hourly data is enough.
2. In the portal, open Network Watcher, then Flow logs, select the flow log, and set the Traffic
   Analytics processing interval to every 60 minutes.
3. Or from the CLI:
   `az network watcher flow-log update --location eastus --resource-group my-rg --name my-flow-log --interval 60`.
4. Confirm the new interval with the list command above.
