Remove Automation rules from analytics rules in Sentinel

rob wood 41 Reputation points
2024-02-26T11:06:36.29+00:00

Hello, This is a Microsoft Sentinel question If an automation rule has been created and added as an automated response in an Analytic rule, is there any way to remove it from the list of automated responses

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
979 questions
0 comments No comments
{count} votes

Accepted answer
  1. Akshay-MSFT 16,026 Reputation points Microsoft Employee
    2024-02-27T11:01:58.28+00:00

    @rob wood

    Thank you for posting your query on Microsoft Q&A, from above description I could understand that you are looking to remove a certain automation rule/automated response from a particular analytics rule.

    Please do correct me if this is not the ask by responding in the comments section.

    The automation rule could be triggered or removed for one or more analytics rule with following way:

    • if you want the automation rule to take effect only on certain analytics rules, specify which ones by modifying the If Analytics rule name contains condition. (This condition will not be displayed if Microsoft Defender XDR is selected as the incident provider.)

    Navigate to the Automation Rule blade > Choose the rule > Update the condition by unchecking the "Analytic rule name" you don't want this automation response to run with and leave rest of the "Analytic rule name".

    User's image

    The rule would disappear from automated response of unchecked analytic rule:

    User's image

    Please "Accept the answer (Yes)" and "share your feedback ". This will help us and others in the community as well.

    Thanks,

    Akshay Kaushik

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful