The security lead needs multi-day visibility into which spokes still talk to the Internet and which NSG rules are hit. What should the engineer enable?
Select an answer to reveal the explanation.
Short Explanation
One packet check won’t map days of spoke chatter. Turn on flow logs and Traffic Analytics so you see Internet talkers and which NSG rules actually get hit.
Full Explanation
Network Watcher flow logs—virtual-network flow logs on the current path, with NSG flow logs as the legacy name—capture allowed and denied flows over time. Traffic Analytics visualizes that data so teams can see Internet-bound spokes and rule hits across days. IP flow verify answers a single five-tuple question. Sentinel connectors and VM syslog DCRs are separate observability paths and are not the first Network Watcher answer for NSG/VNet flow history.