Forum Discussion
akefallonitis
May 12, 2020Brass Contributor
Alert - Get incident
Hey, I am trying to implement a Logic App with Alert - Get incident with an Azure Sentinel alert trigger and i get the following error when running: {
"error": {
"code": 400,
"so...
akefallonitis
Brass Contributor
Hi Gary very nice!
Just one question what permissions the app needs to have to access and write the incidents ?
GaryBushey
May 12, 2020Bronze Contributor
akefallonitis that was mentioned in the blog post:
One additional step you will need to take is to give this App the Azure Sentinel Reader rights at the some level. You can use either the Subscription, Resource Group, or Log Analytics workspace level and I would recommend the Log Analytics workspace level just for added security.
- akefallonitisMay 12, 2020Brass Contributor
Thanks again did not notice that. One last question the write to the log analytics does not require additional write permissions for the app ?
- GaryBusheyMay 13, 2020Bronze Contributor
akefallonitis Strangely no. I just the app the read permissions and it worked just fine.