Forum Discussion
Alexander_Ceyran
Apr 06, 2020Copper Contributor
Retrieve "dismiss alert" logs in Sentinel
Hello everyone , I hope you all doing well, I'm trying to retrieve the dismiss alerts logs for MCAS in Azure Sentinel using Azure Log Analytics, however I don't have the raw data as usual which...
sammyredo
Sep 24, 2020Copper Contributor
Sarah_Young I am looking to be able to write a playbook, which will close an MCAS alert in Sentinel and dismiss the corresponding alert in MCAS.
Sarah_Young
Microsoft
Sep 24, 2020sammyredo please look at this example in our Github repo:
https://github.com/Azure/Azure-Sentinel/tree/master/Playbooks/Resolve-McasInfrequentCountryAlerts
- sammyredoOct 12, 2020Copper Contributor
Sarah_Young Thank you. This should work