Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support for version 2 flow logs in azurerm_network_watcher_flow_log #5403

Closed
ThomasStubergh opened this issue Jan 15, 2020 · 2 comments · Fixed by #5419
Closed

Support for version 2 flow logs in azurerm_network_watcher_flow_log #5403

ThomasStubergh opened this issue Jan 15, 2020 · 2 comments · Fixed by #5419

Comments

@ThomasStubergh
Copy link

Community Note

  • Please vote on this issue by adding a 👍 reaction to the original issue to help the community and maintainers prioritize this request
  • Please do not leave "+1" or "me too" comments, they generate extra noise for issue followers and do not help prioritize the request
  • If you are interested in working on this issue or have submitted a pull request, please leave a comment

Description

When you enable flow logs on a NSG, the NSG supports two kinds of versions. Version 1 and version 2.

Extract from Azure Portal: "Version 1 logs ingress and egress IP traffic flows for both allowed and denied traffic. Version 2 provides additional throughput information (bytes and packets) per flow."

Azurerm_network_watcher_flow_log therefore should have an option or switch to choose which version of flow logs are needed.

New or Affected Resource(s)

  • azurerm_network_watcher_flow_log

Potential Terraform Configuration

resource "azurerm_network_watcher_flow_log" "test" {
  network_watcher_name = "${azurerm_network_watcher.test.name}"
  resource_group_name  = "${azurerm_resource_group.test.name}"

  network_security_group_id = "${azurerm_network_security_group.test.id}"
  storage_account_id        = "${azurerm_storage_account.test.id}"
  enabled                   = true

  flow_log_version = v1/v2

  retention_policy {
    enabled = true
    days    = 7
  }

  traffic_analytics {
    enabled               = true
    workspace_id          = "${azurerm_log_analytics_workspace.test.workspace_id}"
    workspace_region      = "${azurerm_log_analytics_workspace.test.location}"
    workspace_resource_id = "${azurerm_log_analytics_workspace.test.id}"
  }
}

flow_log_version = v1/v2 beeing a new option.

References

https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-nsg-flow-logging-overview
and
#5059

  • #0000
katbyte pushed a commit that referenced this issue Jan 21, 2020
Fixes #5403

Adds the version argument for the azurerm_network_watcher_flow_log resource.
@katbyte katbyte added this to the v1.42.0 milestone Jan 21, 2020
@ghost
Copy link

ghost commented Jan 27, 2020

This has been released in version 1.42.0 of the provider. Please see the Terraform documentation on provider versioning or reach out if you need any assistance upgrading. As an example:

provider "azurerm" {
    version = "~> 1.42.0"
}
# ... other configuration ...

@ghost
Copy link

ghost commented Mar 28, 2020

I'm going to lock this issue because it has been closed for 30 days ⏳. This helps our maintainers find and focus on the active issues.

If you feel this issue should be reopened, we encourage creating a new issue linking back to this one for added context. If you feel I made an error 🤖 🙉 , please reach out to my human friends 👉 hashibot-feedback@hashicorp.com. Thanks!

@ghost ghost locked and limited conversation to collaborators Mar 28, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants