SOLVED

Sentinel Playbook Issue

%3CLINGO-SUB%20id%3D%22lingo-sub-1083740%22%20slang%3D%22en-US%22%3ESentinel%20Playbook%20Issue%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1083740%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20a%20set%20of%20playbooks%20to%20run%20automatically%20when%20an%20incident%20is%20created%20from%20an%20alert.%20So%20far%20it's%20been%20working%20well%20without%20issues%2C%20until%20today.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20playbook%20hasn't%20been%20running%20for%20the%20alerts%20every%20time.%20It%20will%20run%20for%20a%20handful%2C%20but%20won't%20run%20for%20most.%20Inside%20the%20logic%20app%20page%20for%20the%20playbook%2C%20there%20is%20no%20errors%20that%20appear%20on%20attempted%20runs%20for%20the%20alert.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1084352%22%20slang%3D%22en-US%22%3ERe%3A%20Sentinel%20Playbook%20Issue%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1084352%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F418279%22%20target%3D%22_blank%22%3E%40leoszalkowski%3C%2FA%3E%26nbsp%3BI%20discovered%20today%20that%20our%20subscription%20was%20impacted%20by%20a%20Log%20Analytics%20disruption%20yesterday%20between%20%3CSPAN%3E00%3A28%20and%2004%3A04%20UTC.%20That%20is%20around%20the%20time%20the%20playbooks%20have%20stopped%20working%2C%20and%20are%20still%20being%20impacted.%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1084418%22%20slang%3D%22en-US%22%3ERe%3A%20Sentinel%20Playbook%20Issue%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1084418%22%20slang%3D%22en-US%22%3EIt%20was%20not%20resolved%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F324945%22%20target%3D%22_blank%22%3E%40rodtrent%3C%2FA%3E.%3CBR%20%2F%3E%3CBR%20%2F%3EThe%20issue%20was%20narrowed%20down%20to%20the%20playbook%20running%20in%20one%20of%20the%20tenants%20my%20company%20is%20managing.%20The%20playbook%20is%20getting%20a%20404%3A%20not%20found%20error%20when%20it's%20run.%3CBR%20%2F%3E%3CBR%20%2F%3ENot%20sure%20if%20some%20permissions%20were%20changed%20in%20the%20tenant%20or%20if%20it%20could%20be%20a%20separate%20issue.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1084561%22%20slang%3D%22en-US%22%3ERe%3A%20Sentinel%20Playbook%20Issue%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1084561%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F418279%22%20target%3D%22_blank%22%3E%40leoszalkowski%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ESo%2C%20just%20one%20tenant%20has%20the%20issue%3F%20Where%20was%20the%20original%20Playbook%20created%3F%20Does%20this%20tenant%20reside%20in%20a%20different%20datacenter%2Fregion%3F%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EDoes%20the%20Playbook%20work%20if%20run%20manually%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1084569%22%20slang%3D%22en-US%22%3ERe%3A%20Sentinel%20Playbook%20Issue%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1084569%22%20slang%3D%22en-US%22%3E%3CP%3ESo%20it's%20a%20strange%20issue.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20playbook%20is%20located%20in%20our%20tenant.%20Our%20region%20is%20different%20than%20our%20customers'%20region.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt%20was%20running%20perfectly%20fine%20for%20the%20past%20two%20weeks%2C%20up%20until%20yesterday%20morning%20for%20the%20one%20customer's%20tenant.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20playbook%20runs%20manually%20if%20I%20run%20it%20from%20inside%20of%20the%20incident%20details%20page.%3C%2FP%3E%3CP%3EIt%20does%20not%20run%2C%20however%2C%20if%20I%20go%20to%20the%20specific%20playbook%20overview%20and%20run%20the%20trigger.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1084592%22%20slang%3D%22en-US%22%3ERe%3A%20Sentinel%20Playbook%20Issue%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1084592%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F418279%22%20target%3D%22_blank%22%3E%40leoszalkowski%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWhat%20error%20notification%20do%20you%20receive%20when%20the%20Trigger%20fails%20to%20run%3F%20Anything%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1084595%22%20slang%3D%22en-US%22%3ERe%3A%20Sentinel%20Playbook%20Issue%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1084595%22%20slang%3D%22en-US%22%3E%3CP%3EI%20get%20the%20404%20Not%20Found%20on%20the%20Get%20Incident%20block%20of%20my%20logic%20app.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20I%20try%20to%20diagnose%20the%20issue%20using%20the%20Logic%20App%20Diagnose%20and%20Solve%20Problems%20tool%2C%20I%20get%20this%20error%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3E%22The%20detector%20couldn't%20identify%20the%20subscription%2C%20resource%20group%20or%20workflow%20specified%20in%20the%20URL.%20Please%20check%20your%20link.%22%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1086245%22%20slang%3D%22en-US%22%3ERe%3A%20Sentinel%20Playbook%20Issue%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1086245%22%20slang%3D%22en-US%22%3E%3CP%3EQuick%20update..%20(still%20no%20solution)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20did%20some%20more%20digging%20into%20this%20issue.%20Within%20the%20playbook%20error%2C%20it's%20looking%20like%20the%20playbook%20block%20that's%20throwing%20the%20error%20is%20not%20getting%20the%20correct%20output.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20went%20back%20through%20the%20run%20history%20and%20noticed%20the%20raw%20outputs%20are%20drastically%20different.%20It%20is%20receiving%20different%20header%20information%20and%20no%20body%20information.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1087297%22%20slang%3D%22en-US%22%3ERe%3A%20Sentinel%20Playbook%20Issue%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1087297%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F418279%22%20target%3D%22_blank%22%3E%40leoszalkowski%3C%2FA%3E%26nbsp%3BFYI%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fsentinel-alerts-stopped-running-playbooks%2Fm-p%2F1087210%23M886%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fsentinel-alerts-stopped-running-playbooks%2Fm-p%2F1087210%23M886%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1087304%22%20slang%3D%22en-US%22%3ERe%3A%20Sentinel%20Playbook%20Issue%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1087304%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F324945%22%20target%3D%22_blank%22%3E%40rodtrent%3C%2FA%3E%26nbsp%3BPerfect%2C%20I%20also%20have%20a%20support%20ticket%20open%20with%20Microsoft.%20I%20got%20a%20response%20asking%20for%20some%20more%20information%20but%20still%20waiting%20to%20here%20back.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAs%20of%20today%2C%20all%20of%20our%20playbooks%20are%20not%20working%20now.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EGuess%20it's%20an%20outage%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1087317%22%20slang%3D%22en-US%22%3ERe%3A%20Sentinel%20Playbook%20Issue%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1087317%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F418279%22%20target%3D%22_blank%22%3E%40leoszalkowski%3C%2FA%3E%26nbsp%3BChecking%20on%20it%20now%20that%20I'm%20back%20in%20the%20office.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1087380%22%20slang%3D%22en-US%22%3ERe%3A%20Sentinel%20Playbook%20Issue%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1087380%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F418279%22%20target%3D%22_blank%22%3E%40leoszalkowski%3C%2FA%3E%26nbsp%3BMessage%20me%20your%20ticket%20number.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

I have a set of playbooks to run automatically when an incident is created from an alert. So far it's been working well without issues, until today.

 

The playbook hasn't been running for the alerts every time. It will run for a handful, but won't run for most. Inside the logic app page for the playbook, there is no errors that appear on attempted runs for the alert.

11 Replies
Best Response confirmed by rodtrent (Microsoft)
Solution

@leoszalkowski I discovered today that our subscription was impacted by a Log Analytics disruption yesterday between 00:28 and 04:04 UTC. That is around the time the playbooks have stopped working, and are still being impacted.

It was not resolved @rodtrent.

The issue was narrowed down to the playbook running in one of the tenants my company is managing. The playbook is getting a 404: not found error when it's run.

Not sure if some permissions were changed in the tenant or if it could be a separate issue.

@leoszalkowski 

 

So, just one tenant has the issue? Where was the original Playbook created? Does this tenant reside in a different datacenter/region? 

 

Does the Playbook work if run manually?

So it's a strange issue.

 

The playbook is located in our tenant. Our region is different than our customers' region.

 

It was running perfectly fine for the past two weeks, up until yesterday morning for the one customer's tenant.

 

The playbook runs manually if I run it from inside of the incident details page.

It does not run, however, if I go to the specific playbook overview and run the trigger.

@leoszalkowski 

 

What error notification do you receive when the Trigger fails to run? Anything?

I get the 404 Not Found on the Get Incident block of my logic app.

 

When I try to diagnose the issue using the Logic App Diagnose and Solve Problems tool, I get this error:

 

"The detector couldn't identify the subscription, resource group or workflow specified in the URL. Please check your link."

 

Quick update.. (still no solution)

 

I did some more digging into this issue. Within the playbook error, it's looking like the playbook block that's throwing the error is not getting the correct output. 

 

I went back through the run history and noticed the raw outputs are drastically different. It is receiving different header information and no body information.

 

 

@rodtrent Perfect, I also have a support ticket open with Microsoft. I got a response asking for some more information but still waiting to here back.

 

As of today, all of our playbooks are not working now. 

 

Guess it's an outage?

@leoszalkowski Checking on it now that I'm back in the office.

@leoszalkowski Message me your ticket number.