One of my VMs shows more network activity than I would expect. It's only used on-demand and rarely, yet I see 500KB/minute flowing through it according to the azure metrics. It's not a lot, of course, but I want to understand what is "normal" vs hacking activity.
I would first like to understand whether the Network in/out metric that we see in the portal includes traffic that might be occurring internal to the Azure network (monitoring etc.) in addition to bytes flowing out to the rest of the world. If so, is there a way to see just external-going traffic? Also, what is the expected "natural" flow of data due to normal azure monitoring behavior?
yo