azure-postgres-mysql-server-diagnostic-logs

Slow-query, audit, and server logs may record statements, identities, errors, and sensitive values. No single Azure RBAC action authorizes the downstream destination; its own access control applies.

azurehigh service: azure:postgres-mysql emits ContainsSecret

Where it sits

locationAzure Monitor PostgreSQL/MySQL server log records
location kindlog_field
data kindscredential password api_key access_key secret_key oauth_token connection_string sensitive_data pii customer_data
emits edgeContainsSecret
serviceDB for PostgreSQL/MySQL (azure:postgres-mysql)

Collection recipe

access modeindirect_destination
operationRead configured diagnostic destination
response path$value
encodingjson
params{"resource_id": "\u003cazure-resource-id\u003e"}

References

move · open · esc close