Send mail following the creation of an incident

Maxime CARMONA 60 Reputation points
2024-01-25T16:49:39.75+00:00

In Sentinel, I created an alert about the data of a create table in my workspace. So I subsequently create an incident but I can not send an email following this alert. I would like to know where and how to set the email if I can do it from Sentinel or if I need to return to my workspace ?

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
977 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Clive Watson 5,711 Reputation points MVP
    2024-01-25T20:50:59.3966667+00:00

    Hello, You can add an Automation Rule to your Incident, that calls a Playbook, the Playbook will send the email - there are "send email" templates

    User's image

    Example (very simple) Automation Rule - you just have to add the "send email" Playbook you add from the Content Hub - yours wont say "unknown playbook".

    User's image

    0 comments No comments