Control: Flow logs should be configured for every network security group
Description
Audit for network security groups to verify if flow logs are configured. Enabling flow logs allows to log information about IP traffic flowing through network security group. It can be used for optimizing network flows, monitoring throughput, verifying compliance, detecting intrusions and more.
Usage
Run the control in your terminal:
powerpipe control run azure_compliance.control.network_sg_flowlog_enabled
Snapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run azure_compliance.control.network_sg_flowlog_enabled --share
SQL
This control uses a named query:
network_sg_flowlog_enabled