azure-network-watcher
Expert knowledge for Azure Network Watcher development including troubleshooting, decision making, limits & quotas, security, configuration, and integrations & coding patterns. Use when configuring VNet/NSG flow logs, Traffic Analytics, packet capture, Connection Monitor migration, or VPN monitoring, and other Azure Network Watcher related development tasks. Not for Azure Monitor (use azure-monitor), Azure Virtual Network (use azure-virtual-network), Azure Networking (use azure-networking), Azure Firewall (use azure-firewall).
How do I install this agent skill?
npx skills add https://github.com/microsoftdocs/agent-skills --skill azure-network-watcherIs this agent skill safe to install?
- Gen Agent Trust Hubpass
This skill provides expert guidance for Azure Network Watcher development by referencing official Microsoft documentation. It does not contain any malicious code, obfuscation, or unauthorized data access patterns.
- Socketpass
No alerts
- Snykwarn
Risk: MEDIUM · 1 issue
- ZeroLeakspass
Score: 93/100 · 2 sections analyzed
What does this agent skill do?
Azure Network Watcher Skill
This skill provides expert guidance for Azure Network Watcher. Covers troubleshooting, decision making, limits & quotas, security, configuration, and integrations & coding patterns. It combines local quick-reference content with remote documentation fetching capabilities.
How to Use This Skill
IMPORTANT for Agent: Use the Category Index below to locate relevant sections. For categories with line ranges (e.g.,
L35-L120), useread_filewith the specified lines. For categories with file links (e.g.,[security.md](security.md)), useread_fileon the linked reference file
IMPORTANT for Agent: If
metadata.generated_atis more than 3 months old, suggest the user pull the latest version from the repository. Ifmcp_microsoftdocstools are not available, suggest the user install it: Installation Guide
This skill requires network access to fetch documentation content:
- Preferred: Use
mcp_microsoftdocs:microsoft_docs_fetchwith query stringfrom=learn-agent-skill. Returns Markdown. - Fallback: Use
fetch_webpagewith query stringfrom=learn-agent-skill&accept=text/markdown. Returns Markdown.
Category Index
| Category | Lines | Description |
|---|---|---|
| Troubleshooting | L34-L44 | Diagnosing and fixing outbound connectivity, NSG/admin rule issues, and VPN gateway/on-prem VPN problems, plus automating VPN monitoring with Azure Network Watcher. |
| Decision Making | L45-L51 | Guidance for migrating network monitoring: moving from classic Connection Monitor and Network Performance Monitor tests, and switching NSG flow logs to VNet flow logs. |
| Limits & Quotas | L52-L56 | How to configure and run Network Watcher packet capture, storage and filtering options, and the key limits/quotas (size, duration, concurrency) that apply to captures |
| Security | L57-L65 | Securing Network Watcher: RBAC and least-privilege setup, Zero Trust segmentation with Traffic Analytics, investigating security issues, and protecting VNet flow logs with managed identities. |
| Configuration | L66-L81 | Configuring and managing Network Watcher agents and VNet/NSG flow logs, including schemas, filtering, Traffic Analytics, AKS monitoring, and deployment via ARM, Bicep, and Azure Policy |
| Integrations & Coding Patterns | L82-L87 | Using Network Watcher programmatically: triggering packet captures from Functions alerts, querying Traffic Analytics with KQL, and provisioning VNet flow logs via Terraform. |
Troubleshooting
Decision Making
| Topic | URL |
|---|---|
| Migrate from Connection Monitor classic to new Connection Monitor | https://learn.microsoft.com/en-us/azure/network-watcher/migrate-to-connection-monitor-from-connection-monitor-classic |
| Migrate tests from Network Performance Monitor to Connection Monitor | https://learn.microsoft.com/en-us/azure/network-watcher/migrate-to-connection-monitor-from-network-performance-monitor |
| Migrate from NSG flow logs to VNet flow logs | https://learn.microsoft.com/en-us/azure/network-watcher/nsg-flow-logs-migrate |
Limits & Quotas
| Topic | URL |
|---|---|
| Use Network Watcher packet capture and understand its limits | https://learn.microsoft.com/en-us/azure/network-watcher/packet-capture-overview |
Security
| Topic | URL |
|---|---|
| Configure RBAC permissions for Azure Network Watcher | https://learn.microsoft.com/en-us/azure/network-watcher/rbac-permissions |
| Secure Azure Network Watcher deployment and data access | https://learn.microsoft.com/en-us/azure/network-watcher/secure-network-watcher |
| Investigate network security issues with Traffic Analytics prompts | https://learn.microsoft.com/en-us/azure/network-watcher/traffic-analytics-insights |
| Apply Zero Trust segmentation using Traffic Analytics | https://learn.microsoft.com/en-us/azure/network-watcher/traffic-analytics-zero-trust |
| Secure VNet flow logs with managed identities | https://learn.microsoft.com/en-us/azure/network-watcher/vnet-flow-logs-managed-identity |
Configuration
Integrations & Coding Patterns
| Topic | URL |
|---|---|
| Trigger Network Watcher packet captures from Azure Functions alerts | https://learn.microsoft.com/en-us/azure/network-watcher/packet-capture-alert-triggered |
| Analyze Traffic Analytics data with KQL queries | https://learn.microsoft.com/en-us/azure/network-watcher/traffic-analytics-queries |
| Provision Azure VNet flow logs with Terraform | https://learn.microsoft.com/en-us/azure/network-watcher/vnet-flow-logs-terraform |
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/microsoftdocs/agent-skills/azure-network-watcher">View azure-network-watcher on skillZs</a>