Azure/Azure-Network-Security

Dependencies

g-ali opened this issue · 3 comments

g-ali commented

Hi,
In order for this workbook to function correctly, does the Azure Firewall and log analytics workspace have to be in the same subscription?

I have my firewall in a different subscription and resource group to that of the log analytics workspace.
If I deploy the workbook to the same subscription as the Firewall, I can select the firewall but can't select log analytics workspace.
If I deploy the workbook to the same subscription as the workspace, I can select the workspace but not the Firewall.

Please advise.

Thanks

Hello @g-ali , Log Analytics Workspace is scoped all the way up to your tenant level. So, if you have your Azure firewall in a different subscription from the Log Analytics Workspace, you should be able to have access to your Azure firewall logs. You may want to however confirm write access in both subscriptions

g-ali commented

Hi,
Thanks for the response.
I have checked I have owner permissions on both subscriptions, therefore that should rule out any permissions issues. Would it be possible for me to do a screen share with you? as I must be doing something wrong with regards to the three parameters (Diagnostics Workspace Name, Diagnostics Workspace Subscription and Diagnostics Workspace Resource group. I'm assuming that those 3 parameters translate to my Log Analytics Workspace Name, Log Analytics Workspace Subscription and Log Analytics Resource group?

@g-ali This is correct. The 3 parameters required are mapped appropriately. Log analytics workspace is agnostic and may be used across scopes.
If you are still experiencing this issue, please reach out to the support channel available to your subscription.