Forum Discussion
Alexander_Ceyran
Apr 06, 2020Copper Contributor
Retrieve "dismiss alert" logs in Sentinel
Hello everyone ,
I hope you all doing well, I'm trying to retrieve the dismiss alerts logs for MCAS in Azure Sentinel using Azure Log Analytics, however I don't have the raw data as usual which doesn't enable me to know the log type. Are these activities retrievable by any chance (using KQL, API) ?
Thank you,
Stay safe.
Alexander
- Sarah_Young
Microsoft
Alexander_Ceyran no, you can't retrieve them into your workspace.
It is possible write a playbook from Sentinel that will dismiss the alerts in MCAS, was this what you were trying to achieve?
Sarah
- sammyredoCopper Contributor
Sarah_Young I am looking to be able to write a playbook, which will close an MCAS alert in Sentinel and dismiss the corresponding alert in MCAS.
- Sarah_Young
Microsoft
sammyredo please look at this example in our Github repo:
https://github.com/Azure/Azure-Sentinel/tree/master/Playbooks/Resolve-McasInfrequentCountryAlerts