Share via

Remove Automation rules from analytics rules in Sentinel

rob wood 41 Reputation points
2024-02-26T11:06:36.29+00:00

Hello, This is a Microsoft Sentinel question If an automation rule has been created and added as an automated response in an Analytic rule, is there any way to remove it from the list of automated responses

Microsoft Security | Microsoft Sentinel
0 comments No comments

Answer accepted by question author

Akshay Kaushik 18,026 Reputation points Microsoft Employee Moderator
2024-02-27T11:01:58.28+00:00

@rob wood

Thank you for posting your query on Microsoft Q&A, from above description I could understand that you are looking to remove a certain automation rule/automated response from a particular analytics rule.

Please do correct me if this is not the ask by responding in the comments section.

The automation rule could be triggered or removed for one or more analytics rule with following way:

  • if you want the automation rule to take effect only on certain analytics rules, specify which ones by modifying the If Analytics rule name contains condition. (This condition will not be displayed if Microsoft Defender XDR is selected as the incident provider.)

Navigate to the Automation Rule blade > Choose the rule > Update the condition by unchecking the "Analytic rule name" you don't want this automation response to run with and leave rest of the "Analytic rule name".

User's image

The rule would disappear from automated response of unchecked analytic rule:

User's image

Please "Accept the answer (Yes)" and "share your feedback ". This will help us and others in the community as well.

Thanks,

Akshay Kaushik

Was this answer helpful?

1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.