azure-loganalytics-sentinel-incident-comments

Analyst comments are free-form and may contain credentials, PII, evidence, or copied log data.

azurehigh service: azure:loganalytics emits ContainsSecret

Where it sits

locationMicrosoft.SecurityInsights/incidents/comments properties.message
location kindlog_field
data kindscredential password api_key access_key secret_key oauth_token connection_string sensitive_data pii customer_data
emits edgeContainsSecret
serviceLog Analytics / Sentinel (azure:loganalytics)

Collection recipe

access moderead_api
operationIncident Comments - List
response pathvalue[].properties.message
encodingjson
params{"resource_id": "\u003cazure-resource-id\u003e"}

Required permissions

Microsoft.SecurityInsights/incidents/comments/read

References

move · open · esc close