Forum Discussion

ghlee's avatar
ghlee
Copper Contributor
Dec 17, 2024

Is it possible to set up this playbook for a specific rule incident alarm?

I was wondering if a specific playbook setting is possible for the rules below

RuleName : New Azure Sentinel incident - Authentication Attempt from New Country

  1. Read UserPrincipalName, set_IPAddress value when alarm occurs

     

  2. Automatically send mail to each user by identifying the user-specific mail address with UserPrincipalName and changing the recipient, ip value according to the specified mail form
No RepliesBe the first to reply