azure-loganalytics-sentinel-automation-rule

Automation rules expose conditions, workflow resource IDs, and operator-entered action configuration.

azurehigh service: azure:loganalytics emits ContainsSecret

Where it sits

locationMicrosoft.SecurityInsights/automationRules properties.{triggeringLogic,actions,displayName}
location kindpolicy_document
data kindscredential webhook_secret sensitive_data
emits edgeContainsSecret
serviceLog Analytics / Sentinel (azure:loganalytics)

Collection recipe

access moderead_api
operationAutomation Rules - Get
response pathproperties
encodingjson
params{"resource_id": "\u003cazure-resource-id\u003e"}

Required permissions

Microsoft.SecurityInsights/automationRules/read

References

move · open · esc close