SANS has a slightly dated paper ([1]) about setting up this sort of thing that gives a flavor for how it can work.
I think AWS's VPC Flow Logs are the foundation for better tools (disclaimer, my company develops these tools - [2]). I hope Azure and others follow suit.
[1] https://www.sans.org/reading-room/whitepapers/cloud/security...
[2] https://observable.net/blog/vpc-flow-logs-virtual-private-cl...