Once your Azure environment is prepared, set up a cloud export in the Kentik portal to authorize access and begin ingesting your network telemetry.
.png?sv=2022-11-02&spr=https&st=2026-05-01T08%3A41%3A55Z&se=2026-05-01T08%3A56%3A55Z&sr=c&sp=r&sig=Aik2R%2FRgkfHS7kL4jeDRXlUriM%2Ff14J%2FsC%2Bx51Iv4tM%3D)
Configuration settings for a Kentik cloud export, highlighting Azure observability features.
Configure a New Azure Cloud Export
Go to Settings » Public Clouds in the main nav menu.
Click Create Cloud Export to start the configuration wizard.
Choose Azure Cloud under Provider and Features.
Under Observability Features, select the data types to collect:
Metadata collection (required): Automatically selected.
Flow log collection: Select to collect flow logs.
Help me configure my provider via Powershell: Choose this to receive a Kentik-generated Powershell script for automatic configuration in Azure Cloud Shell, see Automated Configuration.
Firewall Collection: Select to collect Azure firewall logs.
Cloud metrics history: Select to collect Azure metrics with Kentik’s NMS.
Click the green arrow to proceed to the Kentik Export Azure Configuration step.
Select an API Access method by selecting either:
Kentik enterprise application: No additional information is collected in this section.Custom app registration: Enter the following information or choose from the Saved App Registrations (if any):
Application (client) ID: Enter the ID for the custom application.
Directory (tenant) ID: Enter the tenant ID.
Select a credential from the Kentik Credential dropdown or click Create New Secret to create a new secret (see Credentials Settings Dialogs).
Click Save App Registration.
Under Define Azure Default Fields, choose the location from the Location drop-down, as gathered in Find Resource Group and Location.Enter the Subscription ID associated with the Azure directory containing the assets (see Find Azure Subscription ID).
Click Validate Service Principal to authorize the Azure portal to create a Service Principal for Kentik's VNet Flow Exporter. Ensure your Azure role allows granting access to enterprise applications.
IMPORTANT: The Validate Service Principal step in the wizard is only required if you are authenticating via the pre-integrated Kentik Enterprise Application. If you are using a Custom App Registration, skip this button, as you have already manually authorized your Service Principal and assigned permissions in the Azure Portal.
In the Resource Group to Monitor field, enter the resource group gathered in Find Resource Group and Location.
Click Verify Access to ensure permission has been granted to the resource group for all required APIs.
In the Define Storage Account section, enter a unique Storage Account Name for the storage account where logs will be exported.
Notes:
Kentik must access your storage account from the following public Azure IPs:
20.69.189.228and20.69.185.115.If you have a storage account in the WestUS2 region, use these IPs instead:
51.8.214.254and172.171.46.16and contact your account team.
Under Sampling, choose from:
Sampling Rate: After selecting this option, enter a sampling rate in the Sampling Rate field. The value must be between 2 and 2000.
Unsampled: Select this option if you want all flow logs to be sent without sampling.
Click the green arrow to proceed.
Optionally, configure the Azure Metadata Enrichment Scope, see Define Enrichment Scope.
Click the green arrow to proceed
Enter the cloud export name/description or accept the defaults.
Select the appropriate Kentik billing plan for the cloud export from the Billing Plan dropdown.
Click Save to finalize the cloud export and return to the Public Clouds page, where the new export will be listed.
Define Enrichment Scope.png?sv=2022-11-02&spr=https&st=2026-05-01T08%3A41%3A55Z&se=2026-05-01T08%3A56%3A55Z&sr=c&sp=r&sig=Aik2R%2FRgkfHS7kL4jeDRXlUriM%2Ff14J%2FsC%2Bx51Iv4tM%3D)
To optionally configure the network scope for data enrichment, allowing Kentik to enhance your Azure flow data with additional information such as GeoIP and BGP, follow these steps:
In the Subscription IDs box, paste or drag a file containing comma-delimited subscription IDs. This will allow Kentik to view the resource groups associated with these subscriptions.
Note: Ensure that the Subscription ID is not in use by any other company.
A list of the entered Subscription IDs will populate the page, each with an All Resource Groups drop-down listing all resource groups within that subscription. Select the desired resource groups for enrichment.
Notes:
The All Resource Groups dropdown is disabled if the subscription is in use by any other user.
The Subscription IDs box will indicate the number of valid (green checkmark) and invalid (red exclamation) subscriptions.
You can repeat the process to add more subscriptions to the list.
Click Remove to delete subscriptions from the list.
Using Your Cloud Export
Once the setup process is complete, you can view and utilize your cloud export in Kentik:
Cloud Exports List:
Go to Settings » Public Clouds to see the updated list of cloud exports.
A new cloud export will be listed, representing the VNets or NSGs whose logs are pulled from the specified subscription.
Devices Column:
Each VNet/NSG sending flow logs is listed as a cloud device.
Devices are named after their respective VPC subnet.
These names can be used as group-by and filter values in Kentik queries using the Device Name dimension.
Metadata and Mapping:
The collected metadata, for example for subnets and gateways, enables Kentik to automatically map and visualize the topology of your Azure resources in the Kentik Map.
Historical Metrics Collection
Kentik allows for the collection of historical metrics for Azure. Along with real-time metrics, this data can provide a comprehensive view of performance trends and patterns over time.
The collection of historical metrics must be enabled in the configuration of the cloud export. Once enabled, you can view the metrics with the following steps:
From the Kentik portal main menu, go to Settings » Network Monitoring System » Metrics Explorer.
In the Measurement pane of the Metrics Explorer Query Sidebar, select a measurement starting with "/cloud/Azure/", then select from the available metrics using the dropdown. Click Run Query to execute the query.
Edit an Existing Cloud Export
You can modify the settings of an existing Azure cloud export (such as enabling firewall logs, adjusting sampling rates, or changing the enrichment scope) at any time by navigating to Settings » Public Clouds and clicking on your export.
When editing, please note the following regarding the Authorize button:
No Need to Re-Authorize: If your export is already successfully collecting data, you do not need to click the Authorize button again to save your changes. Simply make your adjustments and click Save at the bottom of the dialog.
Custom App Registrations: If you originally configured your export using a Custom App Registration, the UI may default to showing the "Kentik enterprise application" tab when you reopen it. Do not click the Authorize button, as it does not apply to your custom configuration.
