05 Oct 2026 11:57 AM
As per the documentation we should be able to ingest any Azure Platform metrics via the advanced usecase:
I'm badly failing in getting metrics for the resource: Microsoft.Network/vpnGateways directly. If Diagnostic settings and log forwarding are on on the Azure side I can see logs being forwarded that contain the metric data, but metrics itself are not fetched. This is one of the log entries that kind of confirms that the forwarding works:
However the configuration for metric fetch doesn't deliver any metrics, according the The Azure Graph Explorer all the settings are correct:
Is anyone here successfully ingesting non-ootb metrics from Azure?
Thanks!
05 Oct 2026 01:33 PM
Hi,
The metric definition itself looks correct. TunnelIngressBytes, the dimensions ConnectionName, RemoteIP, Instance, and the PT1M time grain are valid for Azure VPN Gateway.
The first thing I would check is the resource type. The configuration currently uses:
Microsoft.Network/vpnGatewayswhile Dynatrace documents Azure VPN Gateway under:
Microsoft.Network/virtualnetworkgatewaysand TunnelIngressBytes is already listed there as a supported metric.
So I would verify the exact resource type of the gateway in Azure Resource Graph and check whether Dynatrace discovers it as vpnGateways or virtualnetworkgateways.
Another important point is that working Diagnostic Settings and log forwarding do not necessarily confirm that metric polling should work. These are separate ingestion paths. Dynatrace polls Azure Monitor Metrics directly through the Azure Monitor APIs, while Diagnostic Settings export the data through a different mechanism.
05 Oct 2026 01:40 PM
Thanks for looking into it!
Microsoft Azure indeed has two different ressources:
https://learn.microsoft.com/en-us/azure/azure-monitor/reference/supported-metrics/microsoft-network-...
and
https://learn.microsoft.com/en-us/azure/azure-monitor/reference/supported-metrics/microsoft-network-...
In this case vpngateways should be the correct one.
So if DT polls the Azure Monitor APIs then there should be an option to check on the Azure side if those vpngateways are available via the monitoring APIs....if that can be configured/restricted there somehow...
05 Oct 2026 02:26 PM
Yes, checking this directly against the Azure Monitor Metrics API would probably be the next best step.
Microsoft.Network/vpnGateways is indeed a separate resource type, and Azure lists TunnelIngressBytes as a supported metric for it, including the REST API metric name.
You can try this:
az monitor metrics list-definitions \
--resource "/subscriptions/<subscription-id>/resourceGroups/<resource-group>/providers/Microsoft.Network/vpnGateways/<gateway-name>" \
--query "[?name.value=='TunnelIngressBytes']"I haven't been able to test this myself, but according to the documentation it should work.
This would tell us whether the metric is actually exposed through Azure Monitor Metrics for that exact resource.
Featured Posts