Forum Discussion
How to mass apply a playbook to all analytic rules at once?
- Jan 18, 2021
HIprintscreen , yes, that option is in preview under a new feature called automation rules. You can sign up for the Sentinel private preview program here: http://aka.ms/securityprp
Regards
hey Javier-Soriano, Is there any option to do Powershell execution to mass apply the playbook to all rules? I was just messing myself and tried below by uploading a JSON file in CLI and the command will create an analytic rule, and in that, we can add a playbook, which worked perfectly.
Import-AzSentinelAlertRule -WorkspaceName "rg-test" -SettingsFile "alertrule.json"
But, I tried the same way to update by doing Update-AzSentinelAlertRule which didn't work saying as attached snip. Is there any specific rule update command which helps to update the playbook configuration?
printscreen Yes, it should be possible using Powershell, but you would need to write a script for that (can't do it with a single command). The script could get read the rules in the file one by one and then use Update-AzSentinelAlertRule.
You can also use the "Automation Rules" feature that is currently in private preview.
Regards
- mattburroughJun 22, 2021MCT
I needed to bulk apply a playbook to all of my rules recently, so I wrote a PS script as Javier suggested. You can find it on my blog or on GitHub.
-Matt
- Javier-SorianoJun 22, 2021
Microsoft
Nice!!