can we auto update Watchlist in azure sentinel?

Copper Contributor

Is there any possible way to update watchlist automatic from some daily updated IOC.

 

Scenario --->

As currently in my organization we have repository where we update IOC in CSV on daily basis, so I want to that CSV data can be auto updated in watchlist of azure sentinel on daily basis........

Any suggestion will be very helpful. Thanks in advance.

1 Reply
You can use the api to perform the updates https://docs.microsoft.com/en-us/rest/api/securityinsights/watchlists/create-or-update - maybe using Logic Apps (Playbooks), this is an example that uses a Watchlist that you maybe able to adapt