Тёмный

Microsoft Sentinel automation rules to manage response | Logic Apps | Automation Rules | Playbooks 

WhiteEyeSecurity(TheRealTechnicalConfiguration)
Подписаться 1,6 тыс.
Просмотров 5 тыс.
50% 1

Do you want this automation to be activated when new incidents (or alerts, in preview) are created? Or any time an incident gets updated?
Automation rules are triggered when an incident is created or updated (the update trigger is now in Preview) or when an alert is created (also in Preview). Recall that incidents include alerts, and that both alerts and incidents are created by analytics rules, of which there are several types, as explained in Detect threats with built-in analytics rules in Microsoft Sentinel.
learn.microsof...
learn.microsof...
azurecloudai.b...

Опубликовано:

 

4 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 7   
@krishnabadrib1706
@krishnabadrib1706 10 месяцев назад
Do Soc analyst L1 will do this in office!
@whiteeyesecuritytherealtec6623
@whiteeyesecuritytherealtec6623 10 месяцев назад
Not sure, Its Depends Usually L2 and L3. Thanks!
@VivekSharma-vy1xk
@VivekSharma-vy1xk 11 месяцев назад
Great content. I followed it step wise for MFA related Incidents. It failed me on 3rd step with error :  ExpressionEvaluationFailed. The execution of template action 'For_each' failed: the result of the evaluation of 'foreach' expression '@triggerBody()?['object']?['properties']?['Alerts']' is of type 'Null'. The result must be a valid array. Am I missing something here?
@Fmd63067
@Fmd63067 2 месяца назад
what is authpriv? failed login attempts in authpriv, Is it like a table of logs?
@whiteeyesecuritytherealtec6623
@whiteeyesecuritytherealtec6623 2 месяца назад
unix.stackexchange.com/questions/59525/difference-between-authpriv-and-auth
@YT_RaniUmesh
@YT_RaniUmesh Год назад
Are data connector , , analytic rule playbook are interconnected?
@whiteeyesecuritytherealtec6623
Yes, In a way.
Далее
Logic Apps for Everyone - A complete guide for anyone!
50:37
Sentinel Analytics Rules Creation Demo
17:31
Просмотров 6 тыс.
Azure Logic Apps Tutorial
26:14
Просмотров 326 тыс.
Microsoft Sentinel and Defender XDR Demo
1:00:17
Просмотров 1,6 тыс.
Getting Started with Logic Apps Standard
22:07
Просмотров 10 тыс.