azure-firewall-diagnostic-log-records
Firewall logs can record URLs, DNS queries, source identities, addresses, and matched payload metadata. No single Azure RBAC action authorizes the downstream destination; its own access control applies.
Where it sits
| location | Azure Firewall application, network, DNS, threat-intelligence, and IDPS log records |
| location kind | log_field |
| data kinds | credential password api_key access_key secret_key oauth_token connection_string sensitive_data pii customer_data |
| emits edge | ContainsSecret |
| service | Azure Firewall (azure:firewall) |
Collection recipe
| access mode | indirect_destination |
| operation | Read configured diagnostic destination |
| response path | $value |
| encoding | json |
| params | {"resource_id": "\u003cazure-resource-id\u003e"} |
References