azure-loganalytics-query-results

Workspace tables can contain credentials, tokens, request content, identities, PII, and customer telemetry.

azurecritical service: azure:loganalytics emits CanReadData

Where it sits

locationLog Analytics query response.tables[].rows[]
location kinddata_record
data kindscredential password api_key access_key secret_key oauth_token connection_string sensitive_data pii customer_data
emits edgeCanReadData
serviceLog Analytics / Sentinel (azure:loganalytics)

Collection recipe

access modedata_plane
operationQuery - Execute
response pathtables[].rows[]
encodingjson
params{"query": "\u003cKQL\u003e", "workspaceId": "\u003cworkspace-id\u003e"}

Required permissions

Microsoft.OperationalInsights/workspaces/query/*/read

References

move · open · esc close