Azure packet investigation
Turn an Azure symptom into exact packet evidence.
Defender for Cloud, Microsoft Sentinel, Azure Monitor, and VNet Flow Logs help identify where and when to investigate. Network Watcher or a workload capture creates the packet record. PacketSafari explains what that record supports.
Vendor services provide signal, context, or packet acquisition. PacketSafari begins after an authorized packet capture exists.
Analysis result out
- Preliminary
- Verification
- Final Report
- SignalFind the entity and time window
- Packet acquisitionCreate or retrieve the PCAP
- PacketSafariTest the question against frames
Evidence depth
Each source answers a different question.
Context and flow metadata are valuable, but they are not raw packet contents. The clean handoff is to use them to scope a capture, then investigate the capture itself.
Azure Activity Log
Subscription-level control-plane events that show what changed, by whom, and when.
Azure Monitor
Metrics and logs that expose timing, availability, saturation, and service symptoms.
VNet Flow Logs
Virtual-network flow records used to scope communicating endpoints, directions, and traffic behavior, not packet contents.
Defender for Cloud / Sentinel
A security signal or correlated incident that defines the affected resources, entities, and investigation window.
Network Watcher Packet Capture
A filtered packet capture collected from a virtual machine and stored for packet-level investigation.
Operator workflow
From cloud symptom to reviewable packet proof.
The workflow is intentionally bounded. PacketSafari does not poll the cloud account or replace the continuous control plane.
Start with the Azure symptom.
Record the resource, NIC, peer, ports, alert time, service path, and the question the operator needs answered.
resource · entity · time windowCapture at the useful boundary.
Use Network Watcher Packet Capture on a supported VM, a workload capture, or an authorized network packet sensor.
authorized · filtered · bounded PCAPTest the cloud hypothesis.
PacketSafari maps the capture, follows the relevant flows, and separates preliminary direction from independent Verification.
frames · filters · flows · timingSend evidence to the owner.
Update the Sentinel case, change a control, repair the service, or escalate with explicit coverage and uncertainty.
reviewable report · next evidenceInvestigation outcomes
Ask the question the packet record can settle.
A useful result is not another generic alert. It is an answer attached to frames, filters, flows, timestamps, decoded fields, coverage, and uncertainty.
Does the packet record support the Sentinel incident hypothesis?
Conversation timing, endpoints, protocol behavior, repeated sequences, payload-visible indicators, and the exact supporting frames.
Did the network or service cause the failed Azure transaction?
Handshake timing, loss and recovery, resets, receiver behavior, request-to-response gaps, and where observed delay accumulates.
Which Azure or application owner can act next?
The observed boundary, peer behavior, protocol state, capture limitations, and a defensible next diagnostic action.
Data boundary
Move the smallest useful packet window.
Choose the resource and time window first. Apply capture filters, storage, and retention policy in the Azure environment. Then use the SaaS, dedicated, or on-premises path authorized for that packet data.
Review deployment boundariesAzure + PacketSafari

