Azure Public IP Addresses
Azure Public IP Addresses are used by internet resources to communicate inbound to resources in Azure. A public IP address is a resource with its own properties and can be associated with other Azure resources like NAT gateways, Application gateways, and more. This integration helps in monitoring DDoS notification events, packet dropped rate, TCP, and UDP data throughput.
Log and metric types
For Azure Public IP addresses, you can collect the following logs and metrics:
- Resource logs. To learn more about the different resource log category types collected for Azure Public IP addresses, refer to the Azure documentation.
- Platform Metrics for Azure Public IP addresses. These metrics are available in Microsoft.Network/publicIPAddresses namespace. For more information on supported metrics, refer to Azure documentation.
Setup
Configure collector
Create a hosted collector if not already configured. Make sure you create the required sources in this collector.
Configure logs collection
Azure service sends monitoring data to Azure Monitor, which can then stream data to Eventhub. Sumo Logic supports collecting logs from Azure Monitor using our Azure Event Hubs source.
You must explicitly enable diagnostic settings for each Public IP resource you want to monitor. You can forward logs to the same event hub provided they satisfy the limitations and permissions as described here.
When you configure the event hubs source, plan your source category to ease the querying process. A hierarchical approach allows you to make use of wildcards. For example: Azure/PublicIP/Logs.
In this section, you will configure a pipeline for shipping diagnostic logs from Azure Monitor to an Event Hub.
- To set up the Azure Event Hubs source in Sumo Logic, refer to Azure Event Hubs Source for Logs.
- To create the Diagnostic settings in the Azure portal, refer to the Azure documentation. Perform the steps below for each Public IP resource that you want to monitor.
- Choose
Stream to an event hubas the destination. - Select
allLogs. - Use the Event hub namespace and Event hub name configured in the previous step in the destination details section. You can use the default policy
RootManageSharedAccessKeyas the policy name.
- Choose
Configure metrics collection
When you configure the Azure Metrics Source, plan your source category to ease the querying process. A hierarchical approach allows you to make use of wildcards. For example: Azure/PublicIP/Metrics.
To set up the Azure Metrics source in Sumo Logic, refer to Azure Metrics Source.
Troubleshooting
Metrics collection via Azure Metrics Source
To troubleshoot metrics collection via Azure Metrics Source, follow the instructions in Troubleshooting Azure Metrics Source.