Forum Discussion

Pranesh1060's avatar
Pranesh1060
Brass Contributor
Feb 10, 2020

Defender ATP Connector in Logic Apps-Azure Sentinel

Hi,

 

I see that there is a connector available for Defender ATP while creating a new playbook in Sentinel. However I am not sure how exactly does it work. I haven't come across any use cases for that. Is it in any way related to Sentinel or is it just for Logic Apps? As we know in DATP multiple alerts constitutes of 1 incident, so when you create an analytical rule in Sentinel for DATP, it usually comes up with more than 3 results of which two of them are same and belong to the same hostname with the same info. So it makes it a bit difficult to create tickets in SNOW for them because you never know how many tickets will get created automatically. Is there a way around it to ignore the duplicate alerts and take only 1 alert?

 

P.S: The second part of the post is the actual requirement, first part is to see if the connector can be leveraged to fulfill the requirement.

1 Reply

Resources