azure-loganalytics-sentinel-automation-rule
Automation rules expose conditions, workflow resource IDs, and operator-entered action configuration.
Where it sits
| location | Microsoft.SecurityInsights/automationRules properties.{triggeringLogic,actions,displayName} |
|---|---|
| location kind | policy_document |
| data kinds | credential webhook_secret sensitive_data |
| emits edge | ContainsSecret |
| service | Log Analytics / Sentinel (azure:loganalytics) |
Collection recipe
| access mode | read_api |
|---|---|
| operation | Automation Rules - Get |
| response path | properties |
| encoding | json |
| params | {"resource_id": "\u003cazure-resource-id\u003e"} |
Required permissions
Microsoft.SecurityInsights/automationRules/read