azure-nsg-flow-log-records

Flow logs record source/destination addresses, ports, decisions, and traffic metadata that may be sensitive. No single Azure RBAC action authorizes the downstream destination; its own access control applies.

azurehigh service: azure:nsg emits CanReadData

Where it sits

locationNetwork Watcher NSG/virtual network flow-log records
location kindlog_field
data kindssensitive_data pii customer_data
emits edgeCanReadData
serviceNetwork Security Groups (azure:nsg)

Collection recipe

access modeindirect_destination
operationRead configured flow-log storage or Traffic Analytics destination
response path$value
encodingjson
params{"resource_id": "\u003cazure-resource-id\u003e"}

References

move · open · esc close