Forum Discussion
Playbook (Logic App) - trigger - When Azure Sentinel incident creation rule was triggered
- Ofer_ShezafJan 11, 2021
Microsoft
PrashTechTalk : I am not aware that the private preview does not work. That said, the feature will be supported as part of a larger motion to enhance Sentinel automation, called automatoin rules, which is entering private preview as we speak.
- SocInABoxOct 13, 2021Iron ContributorHi everyone,
Do these logic apps/playbooks still need to be attached to every single analytics rule?
I'd like to create a 'global' playbook to add contextual information to every incident.
eg. apply MITRE SHIELD information to every incident's comment section.
I'm not eager to go to all 300 analytic rules and assign a playbook.- GaryBusheyOct 13, 2021Bronze Contributor
SocInABox If you are using the Incident trigger in a playbook, you can use the Automation rules feature of Azure Sentinel to have that playbook automatically run for any incident that gets created.
https://docs.microsoft.com/en-us/azure/sentinel/automate-incident-handling-with-automation-rules
- PrashTechTalkJan 11, 2021Brass Contributor
Ofer_Shezaf - Playbook is not listed at the automated response section of the analytics rule (when in edit). Tenant is registered for private preview but sadly none of the playbook using new trigger displays in the automated response list.