AzureStatic-verified

Flow Logs that Are On, Kept, and Analysed

enabled = false creates a flow log that logs nothing; a retention policy that is off keeps the JSON blobs until somebody deletes the storage account; and without Traffic Analytics nobody ever opens them. Every target is created enabled, retention defaults to 90 days, and Traffic Analytics is on whenever a workspace is given - raw blobs with no aggregation have to be asked for.

terraformAzureazure
azure-flow-logsvizier v1.2.0

Verification

Static-verified

Passed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).

Conformance

  • Static validation (fmt · validate · tflint)
  • Security scan clean (Checkov)
  • Plan tests (mocked: validation rules · outputs)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live test pending (no cloud run yet)

Last verified 2026-09-14 · how we verify

Use it from the registry

terraform · opentofu
module "flow_logs" {
  source  = "www.iac-bazaar.com/iac-bazaar/azure-flow-logs/azure"
  version = "1.0.0"
}

Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.

Inputs & outputs

Create a free account to read this module's contract

The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.

A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.

Documentation

azure-flow-logs

Network flow logs that are switched on, kept long enough, and analysed. Works with Terraform and OpenTofu (>= 1.6), azurerm provider >= 4.0, < 5.0.

enabled = false creates a flow log that logs nothing. The resource exists, the portal lists it, and no flow is written. Every target here is created enabled.

Retention is on the storage account. Flow logs land as JSON blobs; with no retention policy they are kept until somebody deletes them - forever, or the first time somebody cleans up the account. Ninety days is the floor most frameworks ask for; 0 keeps them forever on purpose; fewer than 90 needs accept_short_retention.

Without Traffic Analytics, a flow log is a bucket of JSON. Nobody opens raw flow records. Traffic Analytics aggregates them into a Log Analytics workspace where a query can answer who talked to what. Off by default in the API; on here whenever a workspace is given, and refused otherwise without accept_no_traffic_analytics.

The target decides what is seen. VNet flow logs record every flow in the network, including ones no NSG touches; NSG flow logs are on a retirement path. Target the VNet.

Verification

Static validation runs tofu fmt, init, validate, tflint and checkov. This module has not yet had a live test, so it is published as statically validated with its live test pending and does not carry the live-tested mark.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Usage

Related modules