azure-loganalytics-query-results
Workspace tables can contain credentials, tokens, request content, identities, PII, and customer telemetry.
azurecritical
service: azure:loganalytics
emits CanReadData
Where it sits
| location | Log Analytics query response.tables[].rows[] |
| location kind | data_record |
| data kinds | credential password api_key access_key secret_key oauth_token connection_string sensitive_data pii customer_data |
| emits edge | CanReadData |
| service | Log Analytics / Sentinel (azure:loganalytics) |
Collection recipe
| access mode | data_plane |
| operation | Query - Execute |
| response path | tables[].rows[] |
| encoding | json |
| params | {"query": "\u003cKQL\u003e", "workspaceId": "\u003cworkspace-id\u003e"} |
Required permissions
Microsoft.OperationalInsights/workspaces/query/*/read
References