Aug 12 2020 03:35 AM
Aug 12 2020 03:35 AM
i am attempting to use the trigger "When Azure Sentinel incident creation rule was triggered" that's in preview.
but the playbook is not triggered even if i know that i have a new incident in Sentinel
what's missing from the configuration?
Aug 12 2020 08:53 AM
@erlendoyen You are probably not going to get much help here as, like you said, the feature is in private preview and we are unable to discuss it. There should be some email addresses in the preview documents that you can use to ask for assistance.
Aug 12 2020 09:01 AM
Aug 12 2020 09:05 AM
@erlendoyen I think what is happening is the Incident trigger is showing up when creating Playbooks but you still need to be part of the private preview to use it. I am trying to get verification of this and if I am wrong I will let you know.
Aug 12 2020 09:21 AM
Aug 19 2020 08:19 AM
@erlendoyen Go to Analytics and click the alert rule that you want to get alerted on and edit it. The rule type has to be scheduled for you to be able to trigger the playbook. Go to automated response type and select the playbook/logic app that you created and save it.
It's kind of confusing but you will have to do it for every alert rule and it doesn't do it for every rule automatically as the logic app suggests.
Oct 15 2020 11:54 AM
@Ofer_Shezaf Is this the only option to trigger a playbook against an incident?
The first option which I am able to use Only triggers against generated alerts.
Is there any other option you know of, if I want to trigger a playbook with an Incident?
Oct 18 2020 02:54 PM
Oct 19 2020 09:22 AM
Private previews tend to move pretty fast with Sentinel. Worth the wait on the new activity.
If you need something sooner you can schedule a query against the incidents table using the "Run query and list results" activity. https://azurecloudai.blog/2020/09/23/sentinel-email-notification-logic-app/
Oct 21 2020 12:18 PM
Jan 11 2021 03:22 AM
Jan 11 2021 03:28 AM
@PrashTechTalk : I am not aware that the private preview does not work. That said, the feature will be supported as part of a larger motion to enhance Sentinel automation, called automatoin rules, which is entering private preview as we speak.
Jan 11 2021 09:07 AM
@Ofer_Shezaf - Playbook is not listed at the automated response section of the analytics rule (when in edit). Tenant is registered for private preview but sadly none of the playbook using new trigger displays in the automated response list.
Mar 11 2021 08:21 PM
What is the GA date for this feature in logic apps? Is there anybody who is aware of this?
Mar 11 2021 11:30 PM
Mar 17 2021 03:16 PM
Mar 24 2021 05:12 AM
This great feature is on GA, now !!!
Thank you !!
Oct 12 2021 06:23 PM