Forum Discussion
ghlee
Dec 17, 2024Copper Contributor
Is it possible to set up this playbook for a specific rule incident alarm?
I was wondering if a specific playbook setting is possible for the rules below
RuleName : New Azure Sentinel incident - Authentication Attempt from New Country
- Read UserPrincipalName, set_IPAddress value when alarm occurs
- Automatically send mail to each user by identifying the user-specific mail address with UserPrincipalName and changing the recipient, ip value according to the specified mail form
No RepliesBe the first to reply