azure-loganalytics-saved-search-query
Saved KQL and metadata can embed literal keys, identifiers, or sensitive investigation logic.
Where it sits
| location | Microsoft.OperationalInsights/workspaces/savedSearches.properties.{query,displayName,category,tags} |
| location kind | query_text |
| data kinds | credential password api_key access_key secret_key oauth_token connection_string sensitive_data |
| emits edge | ContainsSecret |
| service | Log Analytics / Sentinel (azure:loganalytics) |
Collection recipe
| access mode | read_api |
| operation | Saved Searches - Get |
| response path | properties |
| encoding | json |
| params | {"resource_id": "\u003cazure-resource-id\u003e"} |
Required permissions
Microsoft.OperationalInsights/workspaces/savedSearches/read
References