Werk #22295: Azure VNet Gateway: fix tunnel ingress, egress and packet drop values
| Component | Checks & agents | ||||
| Title | Azure VNet Gateway: fix tunnel ingress, egress and packet drop values | ||||
| Date | Sep 16, 2026 | ||||
| Level | Trivial Change | ||||
| Class | Bug Fix | ||||
| Compatibility | Incompatible - Manual interaction might be required | ||||
| Checkmk versions & editions |
|
This werk affects the service "Azure/VNet Gateway" of the azure_v2 special agent and the service "VNet Gateway 'name'" of the deprecated azure special agent.
The values "Tunnel Ingress Bytes", "Tunnel Egress Bytes", "Tunnel Ingress Packet Drop Count" and "Tunnel Egress Packet Drop Count" were requested from Azure Monitor with the aggregation "count". This aggregation returns the number of samples in the interval, not their sum. E.g. a gateway with four tunnels therefore always reported 4 for all four values, regardless of the real traffic and packet loss. With the default levels of the azure_v2 check, the service was permanently CRIT for every gateway with more than one tunnel.
The values are now requested with the aggregation "total". They show the bytes and the dropped packets of the last five-minute interval, summed over all tunnels of the gateway.
The azure_v2 check no longer applies default levels to the packet drop counts. If you want to be alerted on dropped packets, set upper levels in the rule "Azure VNet Gateway" that match the traffic of your gateway.
The names of the performance metrics are unchanged, so the graphs keep their history. Values recorded before this fix are meaningless and only reflect the number of tunnels.
If you configured levels on these values in the rule "Azure VNet Gateway", for example to silence the false CRIT state, review them after the update. They now apply to real data.