01-13-2021 05:21 PM
I created a playbook using an Azure Sentinel Incident creation trigger, which shows up as in preview.
I can test everything from the playbook itself: it's able to generate an email and/or slack message depending on the situation.
However, when going to azure sentinel incident rule settings, no playbook show up as available.
I can confirm that if I list all configured playbooks, that one shows an Azure Sentinel Incident (preview) trigger kind.
01-14-2021 12:32 AM - edited 01-14-2021 12:37 AM
@mjamati Is the Analytics rule with which you are trying to add the Playbook a custom rule created by you or default one/Fusion Rule built by Microsoft?
For Fusion/Default rule created by Microsoft, you won't be able to attach a Playbook. The feature is currently not in Public Preview.
01-14-2021 01:37 AM