One automation response for all incidents

Prasenna Kannan 436 Reputation points
2020-11-30T07:44:17.34+00:00

Hello,

I have created analytic rules (Scheduled, Microsoft Security Solution) based incident definition in my Sentinel.

As part of the incidents, I wanted to trigger an automation response whenever an incident is created. The automation response should be in the form of mail alert.

I can get into the individual incident definition and set automation response. However, can I set an automation response at a single place and let all the analytic rule definition can follow the automation response?

Thanks,
Prasenna

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,065 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Marilee Turscak-MSFT 36,411 Reputation points Microsoft Employee
    2020-12-02T02:03:56.863+00:00

    Hi @Prasenna Kannan ,

    Your best bet would be to create an Azure Logic App Playbook to alert you whenever an incident is created.

    There is a really good blog post here that describes exactly how to do this.

    There is an existing preview trigger in place in the Sentinel connector where you can create rules and alerts based on "When Azure Sentinel incident creation rule was triggered," but you will need to apply to apply to join the Private Preview program to use this feature.

    Hope this helps!