Microsoft Sentinel Automation Rules Stop Running After One Playbook Closes Incident

ZLT 21 Reputation points
2022-05-24T06:43:16.08+00:00

Hi,

I have an automation rule that includes few playbooks, my question will they all run even one of the playbook closed the incident?
If they will, how can i stop them from running ?

Thanks.

Azure Logic Apps
Azure Logic Apps
An Azure service that automates the access and use of data across clouds without writing code.
Microsoft Security | Microsoft Sentinel
0 comments No comments
{count} votes

Answer accepted by question author
  1. Andrew Blumhardt 10,071 Reputation points Microsoft Employee
    2022-05-24T18:45:31.25+00:00

    All of the linked Playbooks will be triggered each time a new Incident matching the rule criteria is created. Most will complete very quickly. You could manually stop a long-running logic app if needed (at the app recourse blade). You could also revise your playbooks to stop automatically under your desired conditions.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.