Dynamic content from Sentinel connector in Logic App is missing, basically empty.

Roy Yang 20 Reputation points
2023-05-29T13:43:26.1066667+00:00

Hello.

I'm using Sentinel Incident Connector in my Logic App to send SMS when high severity alert is created. But the dynamic content seems to be missing recently -- it worked few weeks ago. All dynamic content I get is empty.

To demonstrate the situation, I added some actions when condition is false, and I created sample alerts with both high and medium severities in Defender for Cloud, which ended up in Sentinel too.

Screenshot 2023-05-29 at 16.33.26

Screenshot 2023-05-29 at 16.34.21 copy

Screenshot 2023-05-29 at 16.38.38

The result is that I did get some SMSs, but all with content:

False condition [Azure Alert]:  [Severity]:   [Start time in UTC]:

So clearly the dynamic content is all missing. I noticed that the Sentinel Incident connector is in preview, but is there anything causing the issue on Azure side? Thanks.

Cheers,

Roy

Azure Logic Apps
Azure Logic Apps
An Azure service that automates the access and use of data across clouds without writing code.
2,873 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
990 questions
0 comments No comments
{count} votes

Accepted answer
  1. Andrew Blumhardt 9,576 Reputation points Microsoft Employee
    2023-05-30T04:26:42.5166667+00:00

    The connector was updated recently I think to add some new threat intelligence actions. You might try recreating to make sure you have the latest version. You can also open a support case in the portal.


0 additional answers

Sort by: Most helpful