Control: Saved-queries in Azure Monitor should be saved in customer storage account for logs encryption
Description
Link storage account to Log Analytics workspace to protect saved-queries with storage account encryption. Customer-managed keys are commonly required to meet regulatory compliance and for more control over the access to your saved-queries in Azure Monitor. For more details on the above, see https://docs.microsoft.com/azure/azure-monitor/platform/customer-managed-keys?tabs=portal\#customer-managed-key-for-saved-queries.
Usage
Run the control in your terminal:
powerpipe control run azure_compliance.control.monitor_log_analytics_workspace_integrated_with_encrypted_storage_account
Snapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run azure_compliance.control.monitor_log_analytics_workspace_integrated_with_encrypted_storage_account --share
SQL
This control uses a named query:
manual_control