Forum Discussion
superjay
Apr 23, 2021Copper Contributor
Run Playbook Action Blank Automation
Hey All, When I select action the then Run Playbook, see screenshot, it get no available items, anyone else had this?
- Apr 23, 2021What is the first step? I think you are using a Playbook which should be triggered by an alert, instead of an incidents.
Incident based Playbooks needs to be configured through automation rules
Alert based Playbooks through the Analytics Rule configuration (in the automation tab)
https://docs.microsoft.com/en-us/azure/sentinel/tutorial-respond-threats-playbook#respond-to-alerts
superjay
Apr 23, 2021Copper Contributor
Sure the attached is from the github playbook that we use to run an IP check against anonymous IP Alerts Thijs Lecomte
Thijs Lecomte
Apr 23, 2021Bronze Contributor
What is the first step? I think you are using a Playbook which should be triggered by an alert, instead of an incidents.
Incident based Playbooks needs to be configured through automation rules
Alert based Playbooks through the Analytics Rule configuration (in the automation tab)
https://docs.microsoft.com/en-us/azure/sentinel/tutorial-respond-threats-playbook#respond-to-alerts
Incident based Playbooks needs to be configured through automation rules
Alert based Playbooks through the Analytics Rule configuration (in the automation tab)
https://docs.microsoft.com/en-us/azure/sentinel/tutorial-respond-threats-playbook#respond-to-alerts
- superjayApr 23, 2021Copper ContributorYep that's solved it, made a test rule and change the triggering to Azure Sentinel Incident (Preview) thanks so much 🙂