azure-openai-content-logging-diagnostics

Request/response metadata and any enabled payload logging can expose prompts, identities, and model output. No single Azure RBAC action authorizes the downstream destination; its own access control applies.

azurehigh service: azure:openai emits ContainsSecret

Where it sits

locationAzure OpenAI diagnostic logs and configured content logging destinations
location kindlog_field
data kindscredential password api_key access_key secret_key oauth_token connection_string sensitive_data pii customer_data
emits edgeContainsSecret
serviceAzure OpenAI / AI Services (azure:openai)

Collection recipe

access modeindirect_destination
operationRead configured diagnostic destination
response path$value
encodingjson
params{"resource_id": "\u003cazure-resource-id\u003e"}

References

move · open · esc close