%3CLINGO-SUB%20id%3D%22lingo-sub-264843%22%20slang%3D%22en-US%22%3EAutomate%20Azure%20Security%20Center%20actions%20with%20Playbooks%20and%20ServiceNow%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-264843%22%20slang%3D%22en-US%22%3E%3CP%3ELogic%20Apps%20provides%20an%20excellent%20way%20to%20automate%20Azure%20Security%20Center%20actions%20like%20responding%20to%20alerts%20or%20recommendations.%3C%2FP%3E%0A%3CP%3EIn%20this%20blogpost%2C%20we%20will%20create%20a%20Logic%20Apps%20playbook%20that%20will%20create%20a%20record%20in%20ServiceNow.%20This%20prevents%20you%20from%20manually%20creating%20a%20ticket%20in%20ServiceNow%20and%20populate%20the%20fields%20that%20the%20playbook%20can%20automatically%20fill%20in%20for%20you.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId-1650249255%22%20id%3D%22toc-hId-1705542471%22%3EAdd%20a%20Security%20Center%20playbook%20to%20integrate%20ServiceNow%3C%2FH2%3E%0A%3CP%3ELogic%20Apps%20has%20out%20of%20the%20box%20integrations%20with%20third%20party%20vendors%20like%20ServiceNow%2C%20this%20makes%20it%20very%20easy%20to%20integrate%20Azure%20Security%20Center.%20We%20can%20leverage%20ServiceNow%20%3CSTRONG%3ERecord%3C%2FSTRONG%3E%20actions%20like%20%3CSTRONG%3E%3CEM%3ECreate%2C%20Delete%2C%20Get%2C%20Update%3C%2FEM%3E%3C%2FSTRONG%3E%2C%20etc.%3C%2FP%3E%0A%3COL%3E%0A%3CLI%3ENavigate%20to%20the%20Azure%20Security%20Center%20portal%20and%20under%20%3CSTRONG%3EAutomation%20and%20Orchestration%3C%2FSTRONG%3E%2C%20select%20%3CSTRONG%3EPlaybooks%3C%2FSTRONG%3E%3C%2FLI%3E%0A%3CLI%3EClick%20on%20%3CSTRONG%3EAdd%20Playbook%3C%2FSTRONG%3E%3C%2FLI%3E%0A%3CLI%3EProvide%20a%20name%20for%20your%20new%20playbook%20like%20%E2%80%9CASC-Alert-To-ServiceNow%E2%80%9D%20and%20fill%20in%20the%20resource%20group%20and%20location%20fields.%20The%20Log%20Analytics%20integration%20offers%20capabilities%20like%20using%20search%20to%20query%20the%20status%20and%20history%20of%20your%20playbooks.%20Click%20on%20%3CSTRONG%3ECreate%3C%2FSTRONG%3E%3C%2FLI%3E%0A%3CLI%3EIn%20the%20%3CSTRONG%3ELogic%20Apps%20Designer%3C%2FSTRONG%3E%20select%20the%20%3CSTRONG%3EBlank%20Logic%20App%3C%2FSTRONG%3E%20template%3C%2FLI%3E%0A%3CLI%3ESearch%20for%20%3CSTRONG%3EAzure%20Security%20Center%3C%2FSTRONG%3E%20and%20select%20%3CSTRONG%3EWhen%20a%20response%20to%20an%20Azure%20Security%20Center%20alert%20is%20triggered%20%3C%2FSTRONG%3Eas%20the%20trigger%3C%2FLI%3E%0A%3C%2FOL%3E%0A%3CP%3E%26nbsp%3B%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20393px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F55105i7E573EC6B97B84C6%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22Triggers%20and%20Actions.png%22%20title%3D%22Triggers%20and%20Actions.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CEM%3ENote%3A%20adding%20the%20Azure%20Security%20Center%20trigger%20makes%20your%20playbook%20visible%20in%20the%20Azure%20Security%20Center%20alerts%20blade%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3E6.%20Click%20on%20%3CSTRONG%3E%2B%20New%20Step%3C%2FSTRONG%3E%20and%20search%20for%20%3CSTRONG%3EServiceNow%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E7.%20Select%20%3CSTRONG%3ECreate%20Record%3C%2FSTRONG%3E%20as%20the%20action%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20354px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F55107i525014B18D1E89F4%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22create%20record%20action.png%22%20title%3D%22create%20record%20action.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E8.%20To%20continue%2C%20you%20need%20to%20create%20a%20%3CSTRONG%3EServiceNow%20connection%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%3CEM%3ENote%3A%20if%20you%20don%E2%80%99t%20have%20a%20ServiceNow%20environment%20you%20can%20sign%20up%20%3CSPAN%3E%3CA%20href%3D%22https%3A%2F%2Fdeveloper.servicenow.com%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehere%3C%2FA%3E%3C%2FSPAN%3E%20for%20a%20developer%20instance%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3E9.%20Fill%20in%20the%20required%20fields%20to%20create%20the%20connection%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20606px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F55108i3CD947958B7CA442%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22Create%20ServiceNow%20connection.png%22%20title%3D%22Create%20ServiceNow%20connection.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E10.%20Now%20you%20need%20to%20pass%20values%20from%20the%20Security%20Center%20alert%20trigger%20so%20that%20we%20can%20automatically%20populate%20the%20ServiceNow%20record.%20For%20creating%20a%20new%20incident%20record%2C%20we%20need%20to%20populate%20at%20least%20the%20%3CSTRONG%3ECaller%3C%2FSTRONG%3E%20and%20%3CSTRONG%3EShort%20description%3C%2FSTRONG%3E%20field%20as%20shown%20in%20the%20ServiceNow%20%3CSTRONG%3EIncident%20New%20Record%3C%2FSTRONG%3E%20screen%3A%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20667px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F55109i36367EA373281A51%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22create%20incident%20in%20SNOW.png%22%20title%3D%22create%20incident%20in%20SNOW.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E11.%20Back%20to%20your%20Logic%20Apps%20Playbook%20ServiceNow%20action%2C%20select%20%3CSTRONG%3EIncident%3C%2FSTRONG%3E%20as%20your%20%3CSTRONG%3ERecord%20Type%3C%2FSTRONG%3E%3A%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20601px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F55111i4E3FED01F2F5212F%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22create%20incident%201%20in%20LogicApps.png%22%20title%3D%22create%20incident%201%20in%20LogicApps.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E12.%20Fill%20in%20the%20values%20for%20at%20least%20%3CSTRONG%3ECaller%3C%2FSTRONG%3E%20and%20%3CSTRONG%3EShort%20Description%3C%2FSTRONG%3E%2C%20but%20you%20can%20add%20any%20alert%20fields%20which%20are%20of%20interest%3A%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20608px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F55113i77E2A413F984FEB7%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22create%20incident%202%20in%20LogicApps.png%22%20title%3D%22create%20incident%202%20in%20LogicApps.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E13.%20Save%20your%20Logic%20Apps%20playbook%2C%20your%20playbook%20should%20look%20like%20this%3A%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20619px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F55115iBA7B4D682F5A6EFF%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22playbook%20highlevel%20view.png%22%20title%3D%22playbook%20highlevel%20view.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E14.%20Switch%20to%20%3CSTRONG%3ESecurity%20Alerts%3C%2FSTRONG%3E%20in%20Azure%20Security%20Center%20(under%20Threat%20Protection).%3C%2FP%3E%0A%3CP%3E15.%20Click%20on%20the%20security%20alert%2C%20you%20should%20see%20something%20similar%20like%20this%3A%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20814px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F55117iC14BA1F4BF4F9D0A%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22DMZ-1%20alert.png%22%20title%3D%22DMZ-1%20alert.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E16.%20Click%20on%20the%20alert%20one%20more%20time%2C%20which%20reveals%20the%20alert%20details%2C%20and%20the%20%3CSTRONG%3EView%20playbooks%20%3C%2FSTRONG%3Ebutton%20becomes%20available%3A%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20257px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F55119i399DA656DFC8AD91%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22Investige%20View%20Playbooks%20button.png%22%20title%3D%22Investige%20View%20Playbooks%20button.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E17.%20Click%20on%20the%20%3CSTRONG%3EView%20playbooks%3C%2FSTRONG%3E%20This%20shows%20which%20playbooks%20are%20available%20in%20Azure%20Security%20Center%3C%2FP%3E%0A%3CP%3E18.%20Click%20on%20the%20%3CSTRONG%3ERun%20%3C%2FSTRONG%3Ebutton%20to%20start%20the%20playbook%20you%20have%20created.%20This%20will%20pass%20the%20alert%20information%20and%20context.%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20800px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F55123i881AC6AE476949D1%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22Run%20playbook.png%22%20title%3D%22Run%20playbook.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CEM%3ENote%3A%20The%20%3CSTRONG%3ERun%20history%3C%2FSTRONG%3E%20tab%20shows%20previously%20invoked%20playbooks%20and%20status%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E19.%20After%20the%20playbook%20has%20ran%20successfully%2C%20you%20can%20see%20the%20record%20created%20in%20ServiceNow%3A%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20976px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F55127i13E899384E82D387%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22Snow%20Incident.png%22%20title%3D%22Snow%20Incident.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CEM%3EHow%3C%2FEM%3E%20%3CEM%3Eto%20automate%20this%20end%20to%20end%3F%20Look%20at%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FSecurity-Identity%2FAzure-Security-Center-amp-automatic-creation-of-an-incident-in%2Fm-p%2F264875%23M347%22%20target%3D%22_blank%22%3Ethis%20%3C%2FA%3Eblogpost%3C%2FEM%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-264843%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ESecurity%20Center%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Microsoft

Logic Apps provides an excellent way to automate Azure Security Center actions like responding to alerts or recommendations.

In this blogpost, we will create a Logic Apps playbook that will create a record in ServiceNow. This prevents you from manually creating a ticket in ServiceNow and populate the fields that the playbook can automatically fill in for you.

 

Add a Security Center playbook to integrate ServiceNow

Logic Apps has out of the box integrations with third party vendors like ServiceNow, this makes it very easy to integrate Azure Security Center. We can leverage ServiceNow Record actions like Create, Delete, Get, Update, etc.

  1. Navigate to the Azure Security Center portal and under Automation and Orchestration, select Playbooks
  2. Click on Add Playbook
  3. Provide a name for your new playbook like “ASC-Alert-To-ServiceNow” and fill in the resource group and location fields. The Log Analytics integration offers capabilities like using search to query the status and history of your playbooks. Click on Create
  4. In the Logic Apps Designer select the Blank Logic App template
  5. Search for Azure Security Center and select When a response to an Azure Security Center alert is triggered as the trigger

 Triggers and Actions.png

Note: adding the Azure Security Center trigger makes your playbook visible in the Azure Security Center alerts blade

6. Click on + New Step and search for ServiceNow

7. Select Create Record as the action

create record action.png

8. To continue, you need to create a ServiceNow connection

Note: if you don’t have a ServiceNow environment you can sign up here for a developer instance

9. Fill in the required fields to create the connection

Create ServiceNow connection.png

 

10. Now you need to pass values from the Security Center alert trigger so that we can automatically populate the ServiceNow record. For creating a new incident record, we need to populate at least the Caller and Short description field as shown in the ServiceNow Incident New Record screen:

create incident in SNOW.png

 

11. Back to your Logic Apps Playbook ServiceNow action, select Incident as your Record Type:

create incident 1 in LogicApps.png

 

12. Fill in the values for at least Caller and Short Description, but you can add any alert fields which are of interest:

create incident 2 in LogicApps.png

 

13. Save your Logic Apps playbook, your playbook should look like this:

playbook highlevel view.png

 

14. Switch to Security Alerts in Azure Security Center (under Threat Protection).

15. Click on the security alert, you should see something similar like this:

DMZ-1 alert.png

 

16. Click on the alert one more time, which reveals the alert details, and the View playbooks button becomes available:

Investige View Playbooks button.png

17. Click on the View playbooks This shows which playbooks are available in Azure Security Center

18. Click on the Run button to start the playbook you have created. This will pass the alert information and context.

Run playbook.png

Note: The Run history tab shows previously invoked playbooks and status

 

19. After the playbook has ran successfully, you can see the record created in ServiceNow:

Snow Incident.png

 

How to automate this end to end? Look at this blogpost