Azure Firewall IDPS Monitoring

%3CLINGO-SUB%20id%3D%22lingo-sub-3069883%22%20slang%3D%22en-US%22%3EAzure%20Firewall%20IDPS%20Monitoring%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3069883%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20all%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Erecently%20we%20have%20upgraded%20Azure%20Firewall%20from%20standard%20to%20premium%2C%20while%20executing%20the%20IDPS%20Logs%20getting%20below%20error.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFirewall%20Logs%20-%20IDPS%20event%20logs%20getting%20below%20error.%3C%2FP%3E%3CP%3EQuery%20%3A%3CBR%20%2F%3E%2F%2F%20IDPS%20event%20logs%3CBR%20%2F%3E%2F%2F%20IDPS%20events.%20These%20logs%20are%20only%20available%20when%20IDPS%20is%20enabled.%3CBR%20%2F%3EAZFWIdpsSignature%3C%2FP%3E%3CP%3EError%20%3A%3C%2FP%3E%3CP%3Eoperator%3A%20Failed%20to%20resolve%20table%20or%20column%20or%20scalar%20expression%20named%20'AZFWIdpsSignature'%3CBR%20%2F%3EIf%20issue%20persists%2C%20please%20open%20a%20support%20ticket.%20Request%20id%3A%209a77fbe8-3c0e-4660-ab98-205bda874bea%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Visitor

Hi all,

 

Recently we have upgraded Azure Firewall from standard to premium, while executing the IDPS Logs getting below error.

 

Firewall Logs - IDPS event logs getting below error.

Query :
// IDPS event logs
// IDPS events. These logs are only available when IDPS is enabled.
AZFWIdpsSignature

Error :

operator: Failed to resolve table or column or scalar expression named 'AZFWIdpsSignature'
If issue persists, please open a support ticket. Request id: 9a77fbe8-3c0e-4660-ab98-205bda874bea

 

NB ! We have also raised case with Microsoft as well.

1 Reply

@vishwakk 

Have you looked in the Azure Diagnostics table - that the normal place for the IDPS logs?  e.g.

 

AzureDiagnostics
| where ResourceType == "AZUREFIREWALLS"
| where OperationName == "AzureFirewallIDSLog"