New Blog Post | How to Create a Deployable Microsoft Sentinel Playbook

%3CLINGO-SUB%20id%3D%22%5C%26quot%3Blingo-sub-3168635%5C%26quot%3B%22%20slang%3D%22%5C%26quot%3Ben-US%5C%26quot%3B%22%3ENew%20Blog%20Post%20%7C%20How%20to%20Create%20a%20Deployable%20Microsoft%20Sentinel%20Playbook%26lt%3B%5C%2Flingo-sub%26gt%3B%3CLINGO-BODY%20id%3D%22%5C%26quot%3Blingo-body-3168635%5C%26quot%3B%22%20slang%3D%22%5C%26quot%3Ben-US%5C%26quot%3B%22%3E%3CP%3E%3CSPAN%20class%3D%22%5C%26quot%3Blia-inline-image-display-wrapper%22%20lia-image-align-inline%3D%22%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Fgxcuf89792%2F%5C%26quot%3Bhttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F348401i0C8DA46744DA0E83%2Fimage-dimensions%2F645x332%3Fv%3Dv2%5C%26quot%3B%22%20width%3D%22%5C%26quot%3B645%5C%26quot%3B%22%20height%3D%22%5C%26quot%3B332%5C%26quot%3B%22%20role%3D%22%5C%26quot%3Bbutton%5C%26quot%3B%22%20title%3D%22AshleyMartin_1-1644942910911.png%22%20alt%3D%22%5C%26quot%3BAshleyMartin_1-1644942910911.png%5C%26quot%3B%22%20%2F%3E%26lt%3B%5C%2Fspan%26gt%3B%26lt%3B%5C%2FP%26gt%3B%5Cn%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CA%20href%3D%22%5C%26quot%3Bhttps%3A%2F%2Fazurecloudai.blog%2F2022%2F02%2F15%2Fhow-to-create-a-deployable-microsoft-sentinel-playbook%2F%3FWT.mc_id%3Dmodinfra-0000-rotrent%5C%26quot%3B%22%20target%3D%22%5C%26quot%3B_blank%5C%26quot%3B%22%20rel%3D%22%5C%26quot%3Bnoopener%20nofollow%20noopener%20noreferrer%22%20nofollow%3D%22%22%20noreferrer%3D%22%22%3EHow%20to%20Create%20a%20Deployable%20Microsoft%20Sentinel%20Playbook%20%E2%80%93%20Azure%20Cloud%20%26amp%3B%20AI%20Domain%20Blog%20(azurecloudai.blog)%26lt%3B%5C%2FA%26gt%3B%26lt%3B%5C%2FP%26gt%3B%5Cn%3C%2FA%3E%3C%2FP%3E%3CP%20class%3D%22%5C%26quot%3Bhas-medium-font-size%5C%26quot%3B%22%3EOne%20of%20the%20things%20about%20Microsoft%20Sentinel%20that%20makes%20it%20a%20great%20product%20to%20build%20community%20around%20is%20how%20easy%20it%20is%20to%20create%20cool%20things%20and%20then%20share%20them.%20A%20lot%20of%20this%20capability%20is%20due%20to%20the%20query%20language%20(KQL)%20and%20how%20easy%20it%20is%20to%20use%20and%20learn.%26lt%3B%5C%2FP%26gt%3B%5Cn%3C%2FP%3E%3CP%20class%3D%22%5C%26quot%3Bhas-medium-font-size%5C%26quot%3B%22%3E%3CEM%3ENot%20a%20KQL%20person%20yet%3F%20Dig%20into%20the%3CSPAN%3E%26nbsp%3B%26lt%3B%5C%2FSPAN%26gt%3B%3CA%20href%3D%22%5C%26quot%3Bhttps%3A%2F%2Faka.ms%2FMustLearnKQL%5C%26quot%3B%22%20target%3D%22%5C%26quot%3B_blank%5C%26quot%3B%22%20rel%3D%22%5C%26quot%3Bnoopener%20nofollow%20noopener%20noreferrer%22%20noreferrer%3D%22%22%3EMust%20Learn%20KQL%20series%26lt%3B%5C%2FA%26gt%3B.%26lt%3B%5C%2FEM%26gt%3B%26lt%3B%5C%2FP%26gt%3B%5Cn%3C%2FA%3E%3C%2FSPAN%3E%3C%2FEM%3E%3C%2FP%3E%3CP%20class%3D%22%5C%26quot%3Bhas-medium-font-size%5C%26quot%3B%22%3EKQL%20powers%20Workbooks%2C%20Hunting%20queries%2C%20Analytics%20Rules%2C%20etc.%2C%20etc.%20But%20one%20area%2C%20the%20Playbooks%2C%20isn%E2%80%99t%20powered%20by%20KQL.%20Playbooks%20are%20based%20on%20Azure%20Logic%20Apps%2C%20and%20the%20logic%20and%20connections%20contained%20in%20a%20Playbook%20workflow%26lt%3B%5C%2FP%26gt%3B%5Cn%3C%2FP%3E%3CP%20class%3D%22%5C%26quot%3Bhas-medium-font-size%5C%26quot%3B%22%3EUnlike%20Workbooks%20where%20you%20can%20simply%20copy%20and%20paste%20the%20JSON%20code%2C%20you%20can%E2%80%99t%20quickly%20deploy%20a%20Microsoft%20Sentinel%20Playbook%20due%20to%20the%20litany%20of%20tenant-specific%20information%20and%20Logic%20App%20connector%20dependencies%20contained%20in%20the%20code.%26lt%3B%5C%2FP%26gt%3B%26lt%3B%5C%2Flingo-body%26gt%3B%3CLINGO-LABS%20id%3D%22%5C%26quot%3Blingo-labs-3168635%5C%26quot%3B%22%20slang%3D%22%5C%26quot%3Ben-US%5C%26quot%3B%22%3E%3CLINGO-LABEL%3EAzure%26lt%3B%5C%2Flingo-label%26gt%3B%3CLINGO-LABEL%3ECloud%20Security%26lt%3B%5C%2Flingo-label%26gt%3B%3CLINGO-LABEL%3EMicrosoft%20Sentinel%26lt%3B%5C%2Flingo-label%26gt%3B%26lt%3B%5C%2Flingo-labs%26gt%3B%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3C%2FLINGO-SUB%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3168635%22%20slang%3D%22en-US%22%3ENew%20Blog%20Post%20%7C%20How%20to%20Create%20a%20Deployable%20Microsoft%20Sentinel%20Playbook%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3168635%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22AshleyMartin_1-1644942910911.png%22%20style%3D%22width%3A%20645px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F348401i0C8DA46744DA0E83%2Fimage-dimensions%2F645x332%3Fv%3Dv2%22%20width%3D%22645%22%20height%3D%22332%22%20role%3D%22button%22%20title%3D%22AshleyMartin_1-1644942910911.png%22%20alt%3D%22AshleyMartin_1-1644942910911.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fazurecloudai.blog%2F2022%2F02%2F15%2Fhow-to-create-a-deployable-microsoft-sentinel-playbook%2F%3FWT.mc_id%3Dmodinfra-0000-rotrent%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EHow%20to%20Create%20a%20Deployable%20Microsoft%20Sentinel%20Playbook%20%E2%80%93%20Azure%20Cloud%20%26amp%3B%20AI%20Domain%20Blog%20(azurecloudai.blog)%3C%2FA%3E%3C%2FP%3E%0A%3CP%20class%3D%22has-medium-font-size%22%3EOne%20of%20the%20things%20about%20Microsoft%20Sentinel%20that%20makes%20it%20a%20great%20product%20to%20build%20community%20around%20is%20how%20easy%20it%20is%20to%20create%20cool%20things%20and%20then%20share%20them.%20A%20lot%20of%20this%20capability%20is%20due%20to%20the%20query%20language%20(KQL)%20and%20how%20easy%20it%20is%20to%20use%20and%20learn.%3C%2FP%3E%0A%3CP%20class%3D%22has-medium-font-size%22%3E%3CEM%3ENot%20a%20KQL%20person%20yet%3F%20Dig%20into%20the%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FMustLearnKQL%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMust%20Learn%20KQL%20series%3C%2FA%3E.%3C%2FEM%3E%3C%2FP%3E%0A%3CP%20class%3D%22has-medium-font-size%22%3EKQL%20powers%20Workbooks%2C%20Hunting%20queries%2C%20Analytics%20Rules%2C%20etc.%2C%20etc.%20But%20one%20area%2C%20the%20Playbooks%2C%20isn%E2%80%99t%20powered%20by%20KQL.%20Playbooks%20are%20based%20on%20Azure%20Logic%20Apps%2C%20and%20the%20logic%20and%20connections%20contained%20in%20a%20Playbook%20workflow%3C%2FP%3E%0A%3CP%20class%3D%22has-medium-font-size%22%3EUnlike%20Workbooks%20where%20you%20can%20simply%20copy%20and%20paste%20the%20JSON%20code%2C%20you%20can%E2%80%99t%20quickly%20deploy%20a%20Microsoft%20Sentinel%20Playbook%20due%20to%20the%20litany%20of%20tenant-specific%20information%20and%20Logic%20App%20connector%20dependencies%20contained%20in%20the%20code.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-3168635%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ECloud%20Security%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMicrosoft%20Sentinel%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Microsoft

AshleyMartin_1-1644942910911.png

How to Create a Deployable Microsoft Sentinel Playbook – Azure Cloud & AI Domain Blog (azurecloudai....

One of the things about Microsoft Sentinel that makes it a great product to build community around is how easy it is to create cool things and then share them. A lot of this capability is due to the query language (KQL) and how easy it is to use and learn.

Not a KQL person yet? Dig into the Must Learn KQL series.

KQL powers Workbooks, Hunting queries, Analytics Rules, etc., etc. But one area, the Playbooks, isn’t powered by KQL. Playbooks are based on Azure Logic Apps, and the logic and connections contained in a Playbook workflow

Unlike Workbooks where you can simply copy and paste the JSON code, you can’t quickly deploy a Microsoft Sentinel Playbook due to the litany of tenant-specific information and Logic App connector dependencies contained in the code.

0 Replies