Edit

Use Log Analytics to examine Azure Application Gateway firewall logs

Summary

Use Log Analytics to examine Azure Application Gateway firewall logs and understand what Azure Web Application Firewall (WAF) evaluates, matches, and blocks. Analyzing these logs helps you identify traffic patterns and security events. For more information about log queries, see Overview of log queries in Azure Monitor.

In this article, you learn about the WAF logs. You can set up other Application Gateway logs in a similar way.

Prerequisites

Make sure to have the following prerequisites:

Send firewall logs to Log Analytics

To export your firewall logs into Log Analytics, see Diagnostic logs for Application Gateway. When you have the firewall logs in your Log Analytics workspace, you can view data, write queries, create visualizations, and add them to your portal dashboard.

Explore firewall log data with example queries

Use the AzureDiagnostics table to view the raw data in the firewall log by running the following query:

AzureDiagnostics 
| where ResourceProvider == "MICROSOFT.NETWORK" and Category == "ApplicationGatewayFirewallLog"
| limit 10

This query looks similar to the following query:

Screenshot of Log Analytics query.

Use the Resource-specific table to view the raw data in the firewall log by running the following query.

AGWFirewallLogs
| limit 10

To learn about the resource-specific tables, see Monitoring data reference.

You can drill down into the data, plot graphs, or create visualizations from here. The following examples show AzureDiagnostics queries that you can use.

Matched or blocked requests by IP

AzureDiagnostics
| where ResourceProvider == "MICROSOFT.NETWORK" and Category == "ApplicationGatewayFirewallLog"
| summarize count() by clientIp_s, bin(TimeGenerated, 1m)
| render timechart

Matched or blocked requests by URI

AzureDiagnostics
| where ResourceProvider == "MICROSOFT.NETWORK" and Category == "ApplicationGatewayFirewallLog"
| summarize count() by requestUri_s, bin(TimeGenerated, 1m)
| render timechart

Top matched rules

AzureDiagnostics
| where ResourceProvider == "MICROSOFT.NETWORK" and Category == "ApplicationGatewayFirewallLog"
| summarize count() by ruleId_s, bin(TimeGenerated, 1m)
| where count_ > 10
| render timechart

Top five matched rule groups

AzureDiagnostics
| where ResourceProvider == "MICROSOFT.NETWORK" and Category == "ApplicationGatewayFirewallLog"
| summarize Count=count() by details_file_s, action_s
| top 5 by Count desc
| render piechart

Add firewall log queries to your dashboard

After you create a query, add it to your dashboard. Select Pin to dashboard in the Log Analytics workspace. When you pin the previous four queries to an example dashboard, you see something like the following illustration.

Screenshot of an Azure dashboard where you can add your query.

References

Backend health, diagnostic logs, and metrics for Application Gateway