Jan 13 2021 05:21 PM
I created a playbook using an Azure Sentinel Incident creation trigger, which shows up as in preview.
I can test everything from the playbook itself: it's able to generate an email and/or slack message depending on the situation.
However, when going to azure sentinel incident rule settings, no playbook show up as available.
I can confirm that if I list all configured playbooks, that one shows an Azure Sentinel Incident (preview) trigger kind.
Jan 14 2021 12:32 AM - edited Jan 14 2021 12:37 AM
@mjamati Is the Analytics rule with which you are trying to add the Playbook a custom rule created by you or default one/Fusion Rule built by Microsoft?
For Fusion/Default rule created by Microsoft, you won't be able to attach a Playbook. The feature is currently not in Public Preview.
Jan 14 2021 01:37 AM
Feb 25 2021 05:12 AM
Sep 30 2021 02:39 AM
@mjamati Bumping this .
I am also unable to add playbooks to a Fusion Rule. I am able to see some playbooks within the "run playbook - action" but not all including the one I wish to use. I also can't see any difference in the playbooks I can and can't see. They are in the same resource group ect.
Sep 30 2021 04:51 AM
@Hcrossley I am able to see the "Advanced Multistage Attack Detection" fusion rule when I am look at the listing of all the rules. (ignore the blank entries in the list, that is another issue)
Sep 30 2021 05:43 AM
@Gary Bushey So my issue is when you select "run a playbook" It then only shows certain logic apps that can be run and not others. But I am unsure why it doesn't show them.
Sep 30 2021 10:31 AM