How can I get sorted Hit count in the Traffic Flows tab in Azure Firewall Policy Analytics?

Karl-Petter Elliot Åkesson 40 Reputation points
2024-11-08T14:43:27.15+00:00

Hi,

we are planning a larger network change and to prepare for that we want to make sure we are aware of the most common traffic patterns within our network. Thus, we turned to Azure Firewall Policy Analytics as it could be a great tool to better understand the traffic flows. Specifically, since it has a Traffic Flows tab!

Investigating the presentation there makes me just confused. In what order are the result presented? I cannot find a single column that the data seems to be sorted after.

How can I get a sorted list based on Hit Count from highest to lowest?

Kind regards,
Karl-Petter

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
685 questions
{count} votes

Accepted answer
  1. ChaitanyaNaykodi-MSFT 26,526 Reputation points Microsoft Employee
    2024-11-12T05:33:56.19+00:00

    @Karl-Petter Elliot Åkesson

    Thank you for getting back and sharing additional details here.

    Though what I noticed now and missed on Friday is that the list seems to be sorted in a way. It lists the 10 with highest Hit Count in descending order for TCP, and then the 10 for HTTPs and does this for each page. See these screenshots.

    Glad you were able to figure it out, I observed the same. This is per design, I think a way to sort this will be to apply a filter on the Protocol, but this will give you a protocol-based hit count and you will have to apply this filter for each protocol present in the logs (I have attached a sample screenshot below)

    User's image

    It will help if you could log a feature request with business reason for this on our feedback portal here so that product team can prioritize this request.

    Another thing I noticed is that the arrow to select ascending/descending with changes direction when you navigate between pages. On odd pages the pointing down arrow is highlighted while on even pages the up arrow is highlighted. I have a video of it but seems I cannot attach or embed videos in the replies.

    Thank you for sharing your observation here. I think the sorting functionality here is broken and the when filtered via protocol the data is by default sorted by Hit_count largest to lowest and cannot be sorted any other way. I am highlighting this issue internally with the product group.

    Please let me know if you have any additional questions or observations. Thank you!

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.