Log Analytics tables for microsoft.network/azurefirewalls

Table Categories Solutions Supports basic log plan Queries
AZFWApplicationRule

Contains all Application rule log data. Each match between data plane and Application rule creates a log entry with the data plane packet and the matched rule's attributes.

security LogManagement Yes Yes
AZFWApplicationRuleAggregation

Contains aggregated Application rule log data for Policy Analytics.

security LogManagement Yes -
AZFWDnsQuery

Contains all DNS Proxy events log data.

security LogManagement Yes Yes
AZFWFatFlow

This query returns the top flows across Azure Firewall instances. Log contains flow information, date transmission rate (in Megabits per second units) and the time period when the flows were recorded. Please follow the documentation to enable Top flow logging and details on how it is recorded.

security LogManagement Yes Yes
AZFWFlowTrace

Flow logs across Azure Firewall instances. Log contains flow information, flags and the time period when the flows were recorded. Please follow the documentation to enable flow trace logging and details on how it is recorded.

resources LogManagement Yes Yes
AZFWIdpsSignature

Contains all data plane packets that were matched with one or more IDPS signatures.

security LogManagement Yes Yes
AZFWInternalFqdnResolutionFailure

Contains all internal Firewall FQDN resolution requests that resulted in failure.

security LogManagement Yes Yes
AZFWNatRule

Contains all DNAT (Destination Network Address Translation) events log data. Each match between data plane and DNAT rule creates a log entry with the data plane packet and the matched rule's attributes.

security LogManagement Yes Yes
AZFWNatRuleAggregation

Contains aggregated NAT Rule log data for Policy Analytics.

security LogManagement Yes -
AZFWNetworkRule

Contains all Network Rule log data. Each match between data plane and network rule creates a log entry with the data plane packet and the matched rule's attributes.

security LogManagement Yes Yes
AZFWNetworkRuleAggregation

Contains aggregated Network rule log data for Policy Analytics.

security LogManagement Yes -
AZFWThreatIntel

Contains all Threat Intelligence events.

security LogManagement Yes Yes
AzureActivity

Entries from the Azure Activity log that provides insight into any subscription-level or management group level events that have occurred in Azure.

resources, audit, security LogManagement No Yes
AzureMetrics

Metric data emitted by Azure services that measure their health and performance.

resources, monitor LogManagement Yes Yes