Virtual Network (VNet) flow logs enable you to capture information about IP traffic flowing through your Virtual Networks for usage monitoring & optimization, troubleshooting connectivity, compliance, and security analysis.
Flow data is sent to Azure Storage accounts. From there, you can access the data and export it to any visualization tool, SIEM (security information and event management) solution, or intrusion detection system (IDS) of your choice. You can also enable Traffic Analytics that aggregates and enriches flow data to provide advanced visibility into user and application activity as well as malicious IP communication in your networks.