Sep 29 2023 01:30 PM
Hey all,
I am relatively new to Sentinel and I've run across a situation I can't seem to resolve. I've enabled the "SentinelIncident" automation rule and I've configured it to run the 'Send-email-with-formatted-incident-report' playbook. I am receiving the emails when incidents happen but the emails are missing some important details. For example, I occasionally get an email entitled " New Azure Sentinel incident - Atypical travel". In the Entities box at the bottom of this email there are 2 columns - Entity and Entity Type. For this type of incident the Entity column shows a GUID with an Entity Type of Account. Can I resolve the GUID to a user name or UPN so that it shows in the email? Without the user name I have to log into Azure to find out which user is responsible for the incident.
Related but probably more advanced, is there a way to give a geolocation for the IP addresses that also show in the Entities box. It would be helpful to know where the Atypical Travel was happening.
TIA
~dgm~
Oct 02 2023 02:33 AM
SolutionOct 02 2023 09:00 AM
Oct 23 2023 07:29 AM
Oct 23 2023 08:33 AM
Press the "New step " button in the Playbook Editor then type in a search for "Run Query"
Oct 23 2023 10:54 AM - edited Oct 23 2023 11:43 AM
Okay, maybe it's not just me being a dummy. I tried using that step but the 'Subscription' field doesn't populate. I figured that it wasn't licensed on my subscription somehow. Guess I need to figure out what's causing this then.
Oct 23 2023 01:20 PM
Have you tried making sure you're not filtering out any subsciptions in the portal settings?
Oct 23 2023 02:17 PM
Thought that might be it for a moment or two - when I looked at the settings it was filtered to 1 subscription. However, I changed the filter to All Subscriptions and the Subscription field still shows "Loading..." for 1-2 seconds then says 'No Items'. I logged out and back in to ensure it wasn't related to the session. Still nothing.
Oct 24 2023 01:05 AM
It can depend what Subscription you need. If its the Sentinel Workspace one, that is available as "Dynamic content" - search for "Subscription" in the box that pops up when you click on the Subscription field
Nov 07 2023 12:09 PM
Thank you with for your help with this. It definitely got me a couple steps closer. I still find myself hunting for the options I need. Is there a Logic Apps dev guide or learning resource someplace? I've looked and can only seem to find the standard MS Docs which don't really give me enough detail.
TIA
~dgm~
Nov 07 2023 02:49 PM
Nov 08 2023 06:19 AM
Once again, thank you for the help. I'll dig around in this and see if there are some answers.
TY
~dgm~
Oct 02 2023 02:33 AM
Solution