Playbook as automated response for all Analytics rules | Azure Sentinel

Antti Kosonen 1 Reputation point
2021-01-15T12:44:22.807+00:00

I have created a playbook that will trigger certain alerts, and I want to set this as an automated response for all rules. I can manually set this playbook as an automated response for any Analytics rule, but how can I set it for all rules, including new rules in the future? Enabling it manually for each rule is tiresome, and prone to mistakes.

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
996 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Marilee Turscak-MSFT 34,546 Reputation points Microsoft Employee
    2021-01-15T22:29:43.017+00:00

    Hi @Antti Kosonen ,

    Are you looking for a way to get alerts whenever there is an incident in Azure Sentinel?

    If so, you can create a logic app and use "When a response to an Azure Sentinel alert is triggered" with the "Send an email" trigger as described in this blog post.

    Let me know if this is what you are looking for or if I am misunderstanding the goal.