turbot/azure_compliance

Query: network_watcher_flow_log_traffic_analytics_enabled

Usage

powerpipe query azure_compliance.query.network_watcher_flow_log_traffic_analytics_enabled

SQL

select
sg.id resource,
case
when sg.enabled and traffic_analytics ->> 'enabled' = 'true' and (traffic_analytics ->> 'trafficAnalyticsInterval')::int between 10 and 60 then 'ok'
else 'alarm'
end as status,
case
when sg.enabled and traffic_analytics ->> 'enabled' = 'true' and (traffic_analytics ->> 'trafficAnalyticsInterval')::int between 10 and 60 then sg.name || ' flowlog traffic analytics enabled.'
else sg.name || ' flowlog traffic analytics disabled.'
end as reason
, sg.resource_group as resource_group
, sub.display_name as subscription
from
azure_network_watcher_flow_log as sg
join azure_subscription sub on sub.subscription_id = sg.subscription_id;

Controls

The query is being used by the following controls: