azure-monitor-diagnostic-setting-destination

Diagnostic settings reveal log destinations and authorization-rule resource identifiers.

azurehigh service: azure:monitor emits ContainsSecret

Where it sits

locationMicrosoft.Insights/diagnosticSettings.properties.{workspaceId,storageAccountId,eventHubAuthorizationRuleId,eventHubName,serviceBusRuleId}
location kindconfig_field
data kindssensitive_data
emits edgeContainsSecret
serviceAzure Monitor / Activity Log (azure:monitor)

Collection recipe

access moderead_api
operationDiagnostic Settings - Get
response pathproperties
encodingjson
params{"resource_id": "\u003cazure-resource-id\u003e"}

Required permissions

Microsoft.Insights/diagnosticSettings/read

References

move · open · esc close