azure-loganalytics-saved-search-query

Saved KQL and metadata can embed literal keys, identifiers, or sensitive investigation logic.

azurehigh service: azure:loganalytics emits ContainsSecret

Where it sits

locationMicrosoft.OperationalInsights/workspaces/savedSearches.properties.{query,displayName,category,tags}
location kindquery_text
data kindscredential password api_key access_key secret_key oauth_token connection_string sensitive_data
emits edgeContainsSecret
serviceLog Analytics / Sentinel (azure:loganalytics)

Collection recipe

access moderead_api
operationSaved Searches - Get
response pathproperties
encodingjson
params{"resource_id": "\u003cazure-resource-id\u003e"}

Required permissions

Microsoft.OperationalInsights/workspaces/savedSearches/read

References

move · open · esc close