Thank you for getting back and providing requested details.In this scenario, I think using Virtual Network flow logs will be useful to analyze the traffic based on the source IP.
- You can have flow logs captured for NIC of the NVA, you can use this article to configure the VNET flow logs and use the target resource as the NIC of the NVA.
- Then use traffic analytics to view the required data. Traffic analytics examines raw flow logs. It then reduces the log volume by aggregating flows that have a common source IP address, destination IP address, destination port, and protocol.
Hope this helps! Please let me know if you have any question. Thank you!
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.