Forum Discussion

DGMalcolm's avatar
DGMalcolm
Iron Contributor
Nov 12, 2021

Simplest way to get email notifications for Analytics Rules

Taking over for a recent employee departure and totally new to the Azure Sentinel space. A couple years of Azure experience so I can get around.

 

I see that the previous admin enabled a bunch of analytics rules and I want to get notifications for some of them. For instance, 'Azure VM Deletion' is something I'd like an email about. I don't see anything in the rule to enable alert notifications.  Thoughts?

 

TIA

~DGM~

    • Ciyaresh's avatar
      Ciyaresh
      Brass Contributor

      m_zorich Do you have this playbook by any chance? I had a edited version of this one myself where I added another row to show entities but deleted the whole playbook by mistake when deleted the resource group. Now I can't find the original version of this playbook anymore. 

      • DGMalcolm's avatar
        DGMalcolm
        Iron Contributor
        You should be able to find that playbook in "Sentinel SOAR Essentials" in the Content Hub.
  • DGMalcolm's avatar
    DGMalcolm
    Iron Contributor
    Great, thank you. This looks entirely doable - even by a rookie like me.

Resources