May 07 2021 02:09 AM
I have created a logic app where trigger is when a response to an Azure Sentinel alert is triggered.
Next step I have added Send an email trigger.
I have added the logic app to automated response of this particular incident.
Although incident is triggering but emails are not getting generated for notification.
What could be the possible reason for this?
May 07 2021 04:46 AM
@deepak198486 This isn't really something we can answer with just that information since there could be a large number of reasons. Any chance you can post at least an image of your workflow?
Also, you state that you are using the Alert trigger but assigning this to an incident. Can you confirm that you are adding this to the Analytic rule and not through the Automation menu entry (which you shouldn't be able to do if you are using the Alert trigger).
Finally, if you are using the Alert trigger, you may want to think about rewriting it to use the Incident Trigger (unless you need to kick it off manually), as the Automation process is much easier than having to assign a playbook to individual Analytic rules.