Jan 19 2021
02:39 AM
- last edited on
Apr 08 2022
10:42 AM
by
TechCommunityAP
Jan 19 2021
02:39 AM
- last edited on
Apr 08 2022
10:42 AM
by
TechCommunityAP
Hi everyone,
I need to create a report on Azure Sentinel that will send its results to selected group of email addresses, once a week.
Does anyone knows how can I achieve that, and if it is even optional?
** Analytics rule is not an option, as it creates an incident.
Thanks !
Jan 19 2021 07:01 AM
1. Create an Azure Monitor Alerts rule, send to an Action group that has the emails required.
or
2. Create a Logic App (Azure Sentinel Playbook); define a 'recurrence" trigger, and run the KQL, and email. Also note, the Rule can trigger a Playbook that sends the email each time the Incident fires (use the Sentinel trigger rather than 'recurrence')