Microsoft.Network/networkWatchers/flowLogs/delete
Microsoft.Network/networkWatchers/flowLogs/delete
Event
Removes a flow-log resource; inspect targetResourceId to distinguish NSG from virtual-network logging and determine scope. Deletion stops that configuration’s collection but does not delete previously stored flow records. NSG flow logs retire September 30, 2027, and new NSG flow logs can no longer be created; planned migration to VNet flow logs is relevant context.
Security Context
Unauthorized deletion of an active configuration can impair cloud logging (T1685.002). It neither changes packet filtering nor proves that every network visibility source is gone. Migration or removal of an already-disabled configuration can be legitimate.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.Network/networkWatchers/flowLogs/delete. Correlate status, subStatus, and final resource state; accepted asynchronous requests may still fail. Request bodies and HTTP details are optional and export-dependent.
Key Fields
| Field | Investigation value |
|---|---|
caller, claims, authorization | Recorded actor and authorization context; verify effective permissions. |
resourceId, correlationId | Exact target and related operations. |
status, subStatus | Outcome, including acceptance versus final completion. |
properties.requestbody, httpRequest | Submitted configuration or request URL where available; secret material may be omitted. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Recover targetResourceId, enabled state, storage destination, retention, and Traffic Analytics settings.
- Check approved NSG-to-VNet migration and confirm replacement logging actually receives data.
- Measure the affected collection interval and preserve historical storage records and other network evidence.
Sample Event
Synthetic scenario. The sample deletes nsg-flow-log-prod, without prior configuration or replacement-flow-log evidence. The resource name alone does not identify its actual coverage.
Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.Network/networkWatchers/flowLogs/delete", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/NetworkWatcherRG/providers/Microsoft.Network/networkWatchers/NetworkWatcher_eastus/flowLogs/nsg-flow-log-prod" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "puid": "1003200000000666", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud", "http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814", "uti": "fldDel208ExampleUtid01", "ver": "1.0" }, "correlationId": "90000000-0000-4000-8000-000100010101", "description": "", "eventDataId": "90000000-0000-4000-8000-000100010110", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T18:35:48.7421005Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000100010111", "operationName": { "value": "Microsoft.Network/networkWatchers/flowLogs/delete", "localizedValue": "Delete Flow Log" }, "resourceGroupName": "NetworkWatcherRG", "resourceProviderName": { "value": "Microsoft.Network", "localizedValue": "Microsoft.Network" }, "resourceType": { "value": "Microsoft.Network/networkWatchers/flowLogs", "localizedValue": "Microsoft.Network/networkWatchers/flowLogs" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/NetworkWatcherRG/providers/Microsoft.Network/networkWatchers/NetworkWatcher_eastus/flowLogs/nsg-flow-log-prod", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "OK", "localizedValue": "OK (HTTP Status Code: 200)" }, "submissionTimestamp": "2026-04-15T18:35:49.3107218Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "OK", "serviceRequestId": null, "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/NetworkWatcherRG/providers/Microsoft.Network/networkWatchers/NetworkWatcher_eastus/flowLogs/nsg-flow-log-prod", "message": "Microsoft.Network/networkWatchers/flowLogs/delete", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001" }, "relatedEvents": []}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1685.002 — Disable or Modify Cloud Log — An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within t...