azure-nsg-flow-log-records
Flow logs record source/destination addresses, ports, decisions, and traffic metadata that may be sensitive. No single Azure RBAC action authorizes the downstream destination; its own access control applies.
Where it sits
| location | Network Watcher NSG/virtual network flow-log records |
| location kind | log_field |
| data kinds | sensitive_data pii customer_data |
| emits edge | CanReadData |
| service | Network Security Groups (azure:nsg) |
Collection recipe
| access mode | indirect_destination |
| operation | Read configured flow-log storage or Traffic Analytics destination |
| response path | $value |
| encoding | json |
| params | {"resource_id": "\u003cazure-resource-id\u003e"} |
References