MicrosoftDocs/azure-docs/articles/network-watcher

Last 20 commits touching this section.

4ae52c3

Apply suggestion from @learn-build-service-prod-03[bot] Co-authored-by: learn-build-service-prod-03[bot] <274428581+learn-build-service-prod-03[bot]@users.noreply.github.com>

ebdc2dd

Update VNet flow logs overview with API Management note Added note about Azure API Management support for VNet Injection and VNet Integration deployment models.

9fe1df5

Add article on monitoring AKS traffic with flow logs (#321067) * Add article on monitoring AKS traffic with flow logs This article explains how to enable AKS traffic visibility in Azure Network Watcher using virtual network flow logs. It covers supported traffic types, how IP addresses appear in flow records, and limitations of the flow logs. * Clarify limitations of AKS traffic flow logs * docs: add Markdown extension to AKS flow logs article Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * docs: add AKS flow logs article to Network Watcher TOC Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Apply batched suggestions from code review Co-authored-by: learn-build-service-prod-10[bot] <274431553+learn-build-service-prod-10[bot]@users.noreply.github.com> * docs: refine AKS flow logs article Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Improve clarity in AKS flow logs documentation Clarified the description of supported traffic types and corrected punctuation in the flow logs section. * Update flow logs note on IP addresses Clarified that flow records contain IP addresses instead of pod names, emphasizing the reassignment of pod IPs over time. * updates --------- Co-authored-by: Srijan Chakraborty <76106446+Srijan-Chak012@users.noreply.github.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: learn-build-service-prod-10[bot] <274431553+learn-build-service-prod-10[bot]@users.noreply.github.com>

5df8a06

Apply suggestion from @learn-build-service-prod-04[bot] Co-authored-by: learn-build-service-prod-04[bot] <274428985+learn-build-service-prod-04[bot]@users.noreply.github.com>

e4e587e

Revise title and prompts for Traffic Analytics insights Updated the title and prompts in the Traffic Analytics insights article for clarity and consistency.

482c194

Enhance traffic analytics insights with AI agent usage (#320893) * docs: add traffic analytics AI insights Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * docs: resolve traffic analytics authoring issues Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * docs: update traffic analytics reviewers Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

6d63d0a

Removed tag in agentless experience in connection troubleshoot Removed preview tag from the section on Agentless experience in Connection Troubleshoot

7676d24

Consolidate Network Watcher Agent update article into manage article (#320268) * docs: fix accuracy issues and restructure update article for auto-upgrade * docs: clarify auto-upgrade doesn't require a reboot * docs: correct Portal update steps to match actual extension list UI * docs: add portal screenshots for enable and update flows * docs: query latest extension version dynamically in bulk update script * docs: merge update article into consolidated Network Watcher Agent manage article * docs: apply Learn Authoring Assistant style suggestions * docs: add missing Resource Manager tabs in Update section * docs: filter CLI and PowerShell version-check commands to just the version * docs: add annotated screenshot for latest version and update list screenshot * docs: restructure latest available version subsection * docs: make Azure CLI code blocks interactive * docs: split Windows/Linux commands into zone pivots in Enable automatic upgrade section * docs: clarify automatic upgrade note and remove redundant restart guidance * docs: rename TOC entry to Network Watcher Agent * docs: apply Windows/Linux zone pivots in Update manually section * docs: merge Latest available version into Check your extension version * docs: update portal steps and screenshots for enable automatic upgrade and update manually * docs: fix ARM template for extension install and simplify automatic upgrade note * docs: add ARM template content for enable automatic upgrade and update manually * docs: update vm-extensions screenshot and refresh ms.date

e51d1a1

Confirm merge from repo_sync_working_branch to main to sync with https://github.com/MicrosoftDocs/azure-docs (branch main) (#320467) * Note that Newtonsoft serialization attributes stop working after migration (#128734) Follow-up to the `AllowSynchronousIO` clarification in #128726 and the *Migrate to asynchronous HTTP stream I/O* section that was added alongside it. That async guidance is correct as written: replacing `ReadToEnd` with `ReadToEndAsync` keeps the same serializer, so a migrated app keeps behaving identically. This PR covers a step of the migration that isn't behavior-preserving. ## Problem The in-process model used *Newtonsoft.Json*. The isolated worker model uses *System.Text.Json* by default. Types that a migrated app binds to usually still carry *Newtonsoft.Json* attributes (`[JsonProperty("customer_name")]` being the common one), and *System.Text.Json* doesn't recognize them. It binds the affected property to its default value and reports nothing: HTTP 200, property `null`, no exception and no log entry. The *JSON serialization* section of this guide covers the serializer switch itself and links to *Customizing JSON serialization* for options and for moving back to JSON.NET. It says nothing about the attributes already sitting on the reader's types. `JsonProperty` and `JsonPropertyName` currently appear nowhere in this guide, its includes, or `dotnet-isolated-process-guide.md`, so a reader whose property silently stops binding has nothing to search for. Measured on `Microsoft.Azure.Functions.Worker` 2.52.0, `Microsoft.Azure.Functions.Worker.Extensions.Http.AspNetCore` 2.1.1, Core Tools 4.13.0, host 4.1051.300.26316: a DTO carrying `[JsonProperty("customer_name")]` binds to `null` on every input path tested while the app stays on *System.Text.Json*, with no diagnostic on any of them. ## Change One file, one added paragraph, nothing removed: note that *Newtonsoft.Json* serialization attributes carried over from the in-process model are ignored by *System.Text.Json* without an error. The paragraph gives the two ways out: replace them with their *System.Text.Json* equivalents, or configure *Newtonsoft.Json* for the layer that handles the payload. ## Notes for review The edited file is an include, `includes/functions-dotnet-migrate-isolated-other-code-changes.md`. It renders inside `articles/azure-functions/migrate-dotnet-to-isolated-model.md`, which is also the file changed by my open PR #128730. The two touch different files and don't conflict, but they land on the same rendered page, so you may want to look at them together. "Configure *Newtonsoft.Json* for the layer that handles the payload" is deliberately unspecific about which layer, because that depends on whether the app uses ASP.NET Core integration. There's a companion change for `articles/azure-functions/dotnet-isolated-process-guide.md` that makes that distinction precise; it's a different file with a different owner, so I'm submitting it separately. Either change stands on its own. * Include Fluent Bit ConfigMap for log collection (#128767) Added Fluent Bit configuration examples for log collection using Azure Files in AKS. and added support limitation. * Document listSecrets access granted by Container Apps built-in roles (#128755) * Document listSecrets access in Container Apps built-in roles Several Container Apps built-in roles define permissions with wildcard patterns that match the listSecrets action, so they grant read access to secret values in plain text even when the role name or description suggests narrower access. - manage-secrets.md: add a 'Permissions for managing secrets' section listing the built-in roles that grant listSecrets, plus a custom role example that omits it. - jobs.md: correct the Permissions section to name the Jobs Contributor and Jobs Operator roles, call out that both grant listSecrets, and fix the custom role action list (executions/read, stop/action, managedEnvironments/read). - security.md: add secrets management best practices covering role review and custom roles. Roles verified against live ARM role definitions and articles/role-based-access-control/built-in-roles/containers.md. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Correct claim that a custom role without listSecrets blocks secret access The job start API accepts a template override that replaces the container image, command, and environment variables for the execution. An identity holding only Microsoft.App/jobs/start/action can therefore run an arbitrary container with the job's secrets injected and read the values from inside it. Omitting listSecrets from a custom role does not prevent this, so the previous guidance was misleading. - jobs.md: replace the vague 'you get access to all the secrets' note with an IMPORTANT callout explaining the override mechanism, and stop presenting the custom role action list as a way to run jobs without secret access. - manage-secrets.md: change the custom role example to a monitor-only role that omits start/action, and add a WARNING covering the start/action escalation path. Verified against the job start REST contract documented in jobs.md and the --image/--command/--env-vars parameters of 'az containerapp job start'. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Clarify Container Apps job permissions and secret access Refine the role guidance after review: - explain that job start can reference retained secrets rather than implying all secrets are injected automatically - qualify managed identity access by container identity availability - link directly to the Jobs - Start REST API - replace Contributor requirements with jobs/start/action - add individual execution read and stop operations to custom roles - correct wildcard and ConnectedEnvironments role descriptions - normalize the permissions table and scope the jobs-specific warning Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Address Container Apps permissions review findings Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Clarify Container Apps secret access guidance Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Update articles/container-apps/jobs.md * Update articles/container-apps/jobs.md Co-authored-by: Craig Shoemaker <craigshoemaker@gmail.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Co-authored-by: Craig Shoemaker <craigshoemaker@gmail.com> * Add FAQ about multiple X-Azure-Ref values (#128749) * Add FAQ about multiple X-Azure-Ref values - question: Why do I see multiple X-Azure-Ref values in my backend application logs when requests pass through Azure Front Door? answer: The X-Azure-Ref value displayed in the client response and Azure Front Door access logs represents the primary request correlation identifier generated by Azure Front Door. Additional X-Azure-Ref values observed only in backend application logs are expected and are internal correlation identifiers generated during request processing within the Azure Front Door platform. These internal identifiers are used by the service for request tracking and diagnostics and don't indicate multiple client requests. * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * docs: remove duplicate 'the' in NSG diagnostics comments (#128783) Co-authored-by: mrchatam <mrchatam@users.noreply.github.com> * Clarify Prometheus counter visibility (#128772) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 09f5c5be-413a-4b74-b070-c848484e0d73 * docs: fix 'enviroment' typo in Data Factory access strategies (#128774) Co-authored-by: mrchatam <mrchatam@users.noreply.github.com> * docs: remove duplicate 'for' in Azure NetApp Files clone FAQ (#128775) Co-authored-by: mrchatam <mrchatam@users.noreply.github.com> * docs: remove duplicate 'to' in private link relocation guide (#128776) Co-authored-by: mrchatam <mrchatam@users.noreply.github.com> * docs: remove duplicate 'the' in Logic Apps Reassert docs (#128777) Co-authored-by: mrchatam <mrchatam@users.noreply.github.com> * docs: remove duplicate 'the' in storage task runs alt-text (#128781) Co-authored-by: mrchatam <mrchatam@users.noreply.github.com> * docs: remove duplicate 'the' in WebJobs deploy alt-text (#128780) Co-authored-by: mrchatam <mrchatam@users.noreply.github.com> * docs: remove duplicate 'to' in Container Apps volume mount error (#128778) Co-authored-by: mrchatam <mrchatam@users.noreply.github.com> * docs: remove duplicate 'to' in Functions identity-based connections (#128779) Co-authored-by: mrchatam <mrchatam@users.noreply.github.com> * docs: remove duplicate 'the' in SignalR Front Door alt-text (#128784) Co-authored-by: mrchatam <mrchatam@users.noreply.github.com> * docs: remove duplicate 'the' in Site Recovery reprotect guide (#128785) Co-authored-by: mrchatam <mrchatam@users.noreply.github.com> * docs: remove duplicate 'the' in Batch upgrade policy note (#128782) Co-authored-by: mrchatam <mrchatam@users.noreply.github.com> * docs: remove duplicate 'the' in Planetary Computer ingestion overview (#128786) Co-authored-by: mrchatam <mrchatam@users.noreply.github.com> * docs: remove duplicate 'the' in IoT Edge downstream device guide (#128787) Co-authored-by: mrchatam <mrchatam@users.noreply.github.com> --------- Co-authored-by: learn-build-service-prod[bot] <113403604+learn-build-service-prod[bot]@users.noreply.github.com> Co-authored-by: Fabian <info@fzankl.de> Co-authored-by: jacobbaek <dubaek@gmail.com> Co-authored-by: Learn Build Service GitHub App <Learn Build Service LearnBuild@microsoft.com> Co-authored-by: Tiago Alves Macambira <tmacam@burocrata.org> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Co-authored-by: Craig Shoemaker <craigshoemaker@gmail.com> Co-authored-by: Jagan Peddabavi <157447885+Jpeddabavi@users.noreply.github.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: mrchatam <chatam@proton.me> Co-authored-by: mrchatam <mrchatam@users.noreply.github.com> Co-authored-by: Kelly Shields <kellyshields@microsoft.com> Copilot-Session: 09f5c5be-413a-4b74-b070-c848484e0d73

9f0b848

Consolidate Windows and Linux Network Watcher Agent articles (#319933) * docs: consolidate Windows and Linux Network Watcher Agent articles * docs: add redirects and update links to merged agent article * Update articles/network-watcher/network-watcher-agent-manage.md Co-authored-by: learn-build-service-prod-02[bot] <274428175+learn-build-service-prod-02[bot]@users.noreply.github.com> * Update articles/network-watcher/network-watcher-agent-manage.md Co-authored-by: learn-build-service-prod-02[bot] <274428175+learn-build-service-prod-02[bot]@users.noreply.github.com> * Update articles/network-watcher/network-watcher-agent-manage.md Co-authored-by: learn-build-service-prod-02[bot] <274428175+learn-build-service-prod-02[bot]@users.noreply.github.com> * Update articles/network-watcher/migrate-to-connection-monitor-from-network-performance-monitor.md Co-authored-by: learn-build-service-prod-02[bot] <274428175+learn-build-service-prod-02[bot]@users.noreply.github.com> * Update articles/network-watcher/connection-monitor-overview.md Co-authored-by: learn-build-service-prod-02[bot] <274428175+learn-build-service-prod-02[bot]@users.noreply.github.com> * Update articles/expressroute/how-to-configure-connection-monitor.md Co-authored-by: learn-build-service-prod-02[bot] <274428175+learn-build-service-prod-02[bot]@users.noreply.github.com> * docs: bump ms.date and link FAQ in related content * docs: flatten Network Watcher Agent TOC node under Prerequisites * docs: add colon to Network Watcher Agent OS pivot prompt * docs: order Linux before Windows in agent OS pivot * docs: consolidate agent media folders and drop duplicate screenshots * docs: replace redundant FAQ link with Enable Network Watcher link * docs: fix terminology and list numbering flagged by PR review * Update articles/network-watcher/migrate-to-connection-monitor-from-network-performance-monitor.md Co-authored-by: learn-build-service-prod-06[bot] <274430002+learn-build-service-prod-06[bot]@users.noreply.github.com> * Update articles/network-watcher/migrate-to-connection-monitor-from-network-performance-monitor.md Co-authored-by: learn-build-service-prod-02[bot] <274428175+learn-build-service-prod-02[bot]@users.noreply.github.com> --------- Co-authored-by: learn-build-service-prod-02[bot] <274428175+learn-build-service-prod-02[bot]@users.noreply.github.com> Co-authored-by: learn-build-service-prod-06[bot] <274430002+learn-build-service-prod-06[bot]@users.noreply.github.com>

806587b

Update articles/network-watcher/rbac-permissions.md Co-authored-by: learn-build-service-prod-03[bot] <274428581+learn-build-service-prod-03[bot]@users.noreply.github.com>

98d4c20

Add read permission for networkConfigurationDiagnostic Added permission for reading Network Configuration Diagnostic results.

69cfe72

Add Terraform Guidance for Virtual Network Flow Logs (#319059) * Add Terraform guidance for VNet flow logs * title and metadata tweaks * Update articles/network-watcher/vnet-flow-logs-terraform.md Co-authored-by: learn-build-service-prod-10[bot] <274431553+learn-build-service-prod-10[bot]@users.noreply.github.com> * Update articles/network-watcher/vnet-flow-logs-terraform.md Co-authored-by: learn-build-service-prod-10[bot] <274431553+learn-build-service-prod-10[bot]@users.noreply.github.com> * Update articles/network-watcher/vnet-flow-logs-terraform.md Co-authored-by: learn-build-service-prod-10[bot] <274431553+learn-build-service-prod-10[bot]@users.noreply.github.com> * laa tweak --------- Co-authored-by: learn-build-service-prod-10[bot] <274431553+learn-build-service-prod-10[bot]@users.noreply.github.com>

4700180

Archive NSG flow log deployment quickstarts (#319110) * Archive NSG flow log deployment quickstarts * remove linked rest api archived article

f075b79

Create VNet flow logs by using an ARM template (#318984) * docs: add VNet flow logs ARM template how-to * tweaks * Update articles/network-watcher/vnet-flow-logs-arm-template.md Co-authored-by: learn-build-service-prod-07[bot] <274430390+learn-build-service-prod-07[bot]@users.noreply.github.com> * docs: add ARM template article to Network Watcher TOC --------- Co-authored-by: learn-build-service-prod-07[bot] <274430390+learn-build-service-prod-07[bot]@users.noreply.github.com>

bead0eb

Create a virtual network flow log by using Bicep (#318938) * docs: add VNet flow logs Bicep quickstart * laa tweaks * docs: convert VNet flow logs article to how-to * Update articles/network-watcher/vnet-flow-logs-bicep.md Co-authored-by: learn-build-service-prod-08[bot] <274430765+learn-build-service-prod-08[bot]@users.noreply.github.com> * tweak * docs: link VNet flow logs sample source * tweak --------- Co-authored-by: learn-build-service-prod-08[bot] <274430765+learn-build-service-prod-08[bot]@users.noreply.github.com>

18b9d76

Update NSG flow log guidance for retirement (#318927) * docs: correct NSG flow log terminology * laa tweaks * tweaks * Update articles/network-watcher/nsg-flow-logs-manage.md Co-authored-by: learn-build-service-prod-02[bot] <274428175+learn-build-service-prod-02[bot]@users.noreply.github.com> * Update articles/network-watcher/nsg-flow-logs-manage.md Co-authored-by: learn-build-service-prod-02[bot] <274428175+learn-build-service-prod-02[bot]@users.noreply.github.com> * docs: remove retired NSG flow log creation guidance * docs: remove unused NSG flow log images * docs: remove stale NSG flow log creation links * Update articles/network-watcher/flow-logs-read.md Co-authored-by: learn-build-service-prod-01[bot] <274427437+learn-build-service-prod-01[bot]@users.noreply.github.com> * Update articles/network-watcher/nsg-flow-logs-migrate.md Co-authored-by: learn-build-service-prod-01[bot] <274427437+learn-build-service-prod-01[bot]@users.noreply.github.com> * Fix minor grammatical errors in migration guide --------- Co-authored-by: learn-build-service-prod-02[bot] <274428175+learn-build-service-prod-02[bot]@users.noreply.github.com> Co-authored-by: learn-build-service-prod-01[bot] <274427437+learn-build-service-prod-01[bot]@users.noreply.github.com> Co-authored-by: Regan Downer <v-rdowner@microsoft.com>

e673133

docs: rename Network Watcher RBAC permissions article (#318923)

aff5d79

formatting correction

abc7598

cda tweaks