Home

Playbook Running

%3CLINGO-SUB%20id%3D%22lingo-sub-903390%22%20slang%3D%22en-US%22%3EPlaybook%20Running%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-903390%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20everyone%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20am%20trying%20to%20create%20a%20simple%20playbook%20that%20whenever%20an%20ASC%20alert%20pops%2C%20it%20will%20send%26nbsp%3B%20an%20email%20message.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20the%20designer%2C%20the%20flow%20looks%20like%20this%3A%3C%2FP%3E%3CP%3E1.%20When%20an%20Azure%20Security%20Center%20alert%20is%20created%3C%2FP%3E%3CP%3E2.%20Send%20an%20email%20(configured%20with%20the%20desired%20options).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20playbook%20is%20saved%20and%20shows%20as%20enabled%2C%20alerts%20are%20happening%20in%20ASC%2C%20yet%20no%20mails.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThere%20is%20no%20frequency%20to%20the%20playbook%20showing%2C%20not%20sure%20if%20there%20should%20be.%3C%2FP%3E%3CP%3EThe%20number%20of%20attempted%20runs%20is%200.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhy%20is%20the%20playbook%20not%20running%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDoes%20the%20subscription%20and%20RG%20where%20the%20playbook%20was%20created%20matter%20in%20any%20way%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20feel%20like%20I'm%20missing%20something%20obvious%20but%20can't%20find%20it.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20for%20the%20assistance.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-904961%22%20slang%3D%22en-US%22%3ERe%3A%20Playbook%20Running%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-904961%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F423097%22%20target%3D%22_blank%22%3E%40GabrielNecula%3C%2FA%3E%26nbsp%3BAre%20you%20sending%20the%20alerts%20into%20Sentinel%20from%20ASC%3F%26nbsp%3B%20If%20not%2C%20you%20would%20probably%20be%20better%20off%20posting%20this%20to%20the%20Azure%20Security%20Center%20group.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

Hello everyone,

 

I am trying to create a simple playbook that whenever an ASC alert pops, it will send  an email message.

 

In the designer, the flow looks like this:

1. When an Azure Security Center alert is created

2. Send an email (configured with the desired options).

 

The playbook is saved and shows as enabled, alerts are happening in ASC, yet no mails.

 

There is no frequency to the playbook showing, not sure if there should be.

The number of attempted runs is 0.

 

Why is the playbook not running?

 

Does the subscription and RG where the playbook was created matter in any way?

 

I feel like I'm missing something obvious but can't find it.

 

Thank for the assistance.

 

1 Reply
Highlighted

@GabrielNecula Are you sending the alerts into Sentinel from ASC?  If not, you would probably be better off posting this to the Azure Security Center group.