azure-firewall-diagnostic-log-records

Firewall logs can record URLs, DNS queries, source identities, addresses, and matched payload metadata. No single Azure RBAC action authorizes the downstream destination; its own access control applies.

azurehigh service: azure:firewall emits ContainsSecret

Where it sits

locationAzure Firewall application, network, DNS, threat-intelligence, and IDPS log records
location kindlog_field
data kindscredential password api_key access_key secret_key oauth_token connection_string sensitive_data pii customer_data
emits edgeContainsSecret
serviceAzure Firewall (azure:firewall)

Collection recipe

access modeindirect_destination
operationRead configured diagnostic destination
response path$value
encodingjson
params{"resource_id": "\u003cazure-resource-id\u003e"}

References

move · open · esc close