A network security group (NSG) includes rules that allow or deny traffic to a virtual network subnet, network interface, or both. When you enable diagnostic logging for an NSG, you can log the following categories of information: Event: Entries are logged for which NSG rules are applied to VMs, based on MAC address. The status for these rules is collected every 60 seconds. Rule counter: Contains entries for how many times each NSG rule is applied to deny or allow traffic. References: https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-nsg-manage-log