Forum Discussion
Alert - Get incident
akefallonitis I just wrote a blog post on doing that. Make sure to read Part 1 and 2 as I changed some of the ways I did the logic app in Part 2. Part 3 gives you a workbook to start from that uses the data.
Hi Gary very nice!
Just one question what permissions the app needs to have to access and write the incidents ?
- GaryBusheyMay 12, 2020Bronze Contributor
akefallonitis that was mentioned in the blog post:
One additional step you will need to take is to give this App the Azure Sentinel Reader rights at the some level. You can use either the Subscription, Resource Group, or Log Analytics workspace level and I would recommend the Log Analytics workspace level just for added security.
- akefallonitisMay 12, 2020Brass Contributor
Thanks again did not notice that. One last question the write to the log analytics does not require additional write permissions for the app ?
- GaryBusheyMay 13, 2020Bronze Contributor
akefallonitis Strangely no. I just the app the read permissions and it worked just fine.