Skip to main content

Responses are generated using AI and may contain mistakes.

CollectorsCloud Collectors Administration Guide

Table of Contents

Prerequisites to Configure the Azure Virtual Network Flow Cloud Collector

Before you configure the Azure Virtual Network Flow Cloud Collector, you must create a Microsoft Entra ID application application and complete the following prerequisites to obtain the relevant information.

Assign the Storage Blob Data Reader Role

Use the following steps to assign the Storage Blob Data Reader role to a storage account in the Azure Portal.

  1. Log in to the Microsoft Azure portal by accessing https://portal.azure.com.

  2. In the left pane, to navigate to your storage account, click Storage accounts.

  3. Click the storage account to which you want to assign the role.

  4. Click + Add and click Add role assignment.

  5. In the Role tab, search for and select Storage Blob Data Reader.

    This role provides read-only access to blob data in the storage account.

  6. Click Next, and assign access to the required User, Group, or Service Principal.

  7. Click Next and then click Review + assign.

Obtain the Storage Account Name

Use the following steps to obtain the storage account name.

  1. Log in to the Microsoft Azure portal.

  2. To navigate to your storage account in the Azure portal, in the left pane, click Storage accounts or search for Storage accounts in the search box and select the account.

  3. Note the account name. The Overview page displays the storage account name.

    Note

    Ensure that you use the same storage account while configuring virtual network flow logs. For more information about creating and editing the virtual network flow logs, see Manage VNet flow logs in the Microsoft documentation.

Obtain the Subscription ID of the Storage Account

Use the following steps to obtain the Subscription ID of the storage account name.

  1. Log in to the Microsoft Azure portal.

  2. To navigate to your storage account in the Azure portal, in the left pane, click Storage accounts or search for Storage accounts in the search box and select the storage account you used to store the logs.

  3. In Data storage, select Containers.

  4. Select the insights-logs-flowlogflowevent container.

  5. In insights-logs-flowlogflowevent, select flowLogResourceID= directory. In this path, copy directory name which is of the format {subscriptionID}_NETWORKWATCHERRG.