Azure Network Watcher on Microsoft Azure
What is Azure Network Watcher?
Azure Network Watcher is a network monitoring and diagnostics service for Azure IaaS resources such as virtual machines, virtual networks, application gateways, and load balancers. It’s not designed for monitoring PaaS services or web analytics.
The service is organized into three areas: monitoring (topology, connection monitor), network diagnostic tools (including IP flow verify, NSG diagnostics, next hop, effective security rules, connection troubleshoot, packet capture, VPN troubleshoot), and traffic tools (flow logs, traffic analytics). Network Watcher is automatically enabled in a region when you create or update a virtual network there, at no extra cost for the activation itself.
Network Watcher is available in all Azure regions and meets GDPR requirements when using European regions.
Core Features
- Topology: interactive visualization of network configuration across multiple subscriptions, resource groups, and locations
- Connection Monitor: continuous end-to-end connection monitoring for Azure and hybrid endpoints
- IP Flow Verify & NSG Diagnostics: check whether packets are allowed or denied by security rules, including which rule is responsible
- Next Hop & Effective Security Rules: diagnose routing issues and view the security rules actually in effect
- Connection Troubleshoot & VPN Troubleshoot: on-demand connection tests and diagnostics for VPN gateway connections
- Packet Capture: remote packet capture at the VM or VM scale set level without installing additional software
- Flow Logs & Traffic Analytics: log IP traffic at the NSG or VNet level with rich visual analysis
Important note: NSG flow logs will be retired by Microsoft on September 30, 2027; new NSG flow logs can no longer be created as of June 30, 2025. Microsoft recommends migrating to VNet flow logs, which offer the same capabilities and address the limitations of NSG flow logs.
Typical Use Cases
Diagnosing connectivity issues: Connection Troubleshoot checks reachability between VMs, application gateways, or other resources and identifies issues like NSG blocks or routing errors.
Traffic analysis: VNet flow logs (or the retiring NSG flow logs) combined with traffic analytics provide insights into network traffic patterns, top talkers, and potential security risks.
Packet-level debugging: Packet Capture enables recording of network packets at the VM level for detailed protocol analysis without installing additional software.
Compliance and security audits: Topology view, effective security rules, and Connection Monitor document network architecture and connectivity for compliance evidence.
Benefits
Network Watcher is automatically provisioned with every virtual network and requires no separate installation. By combining proactive monitoring, on-demand diagnostic tools, and flow-log-based traffic analysis, network issues in Azure can be narrowed down quickly without needing additional agents on the target resources.
Frequently Asked Questions about Azure Network Watcher
What is the difference between Connection Monitor and Connection Troubleshoot?
Connection Monitor is designed for continuous, proactive monitoring and checks connections at regular intervals. Connection Troubleshoot is an on-demand tool for ad-hoc diagnostics of acute connectivity problems at a specific point in time.
What is the difference between NSG flow logs and VNet flow logs?
NSG flow logs log traffic at the network security group level and will be retired on September 30, 2027; new NSG flow logs can no longer be created as of June 2025. VNet flow logs are the successor, logging at the virtual network level and addressing several limitations of NSG flow logs.
How does IP Flow Verify work?
IP Flow Verify checks whether a packet with specific parameters (source/destination IP, port, protocol) is allowed or blocked from or to a VM, and shows which security rule is responsible.
What does Azure Network Watcher cost?
The core capabilities and automatic activation are free; individual features such as Connection Monitor, Packet Capture, or flow logs are billed on a usage basis, plus storage costs for stored logs and captures. Current prices are available on the official Azure Network Watcher pricing page.
Can Network Watcher also monitor on-premises networks?
Network Watcher is focused on Azure resources. For hybrid scenarios, Connection Monitor tests can be configured against on-premises endpoints, provided they are reachable via VPN or ExpressRoute.
How does Network Watcher integrate with Microsoft Sentinel?
Flow log and traffic analytics data can be forwarded to Microsoft Sentinel via a Log Analytics workspace, where it can be used for security analytics, threat detection, and incident response.
Integration with innFactory
As a Microsoft Solutions Partner, innFactory supports you in implementing comprehensive network monitoring strategies with Azure Network Watcher. We help with setup, migrating from NSG flow logs to VNet flow logs, troubleshooting workflows, and integration into existing monitoring systems.
Contact us for a non-binding consultation on Azure Network Watcher.
Typical Use Cases
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.
