azure-frontdoor-access-waf-logs

Front Door logs can record request URIs, client identifiers, and WAF-matched payload fragments. No single Azure RBAC action authorizes the downstream destination; its own access control applies.

azurehigh service: azure:frontdoor emits ContainsSecret

Where it sits

locationFront Door access, health probe, and WAF log records
location kindlog_field
data kindscredential password api_key access_key secret_key oauth_token connection_string sensitive_data pii customer_data
emits edgeContainsSecret
serviceFront Door / CDN (azure:frontdoor)

Collection recipe

access modeindirect_destination
operationRead configured diagnostic destination
response path$value
encodingjson
params{"resource_id": "\u003cazure-resource-id\u003e"}

References

move · open · esc close