July 2023
Beginner to intermediate
338 pages
7h 26m
English
In the previous chapter, we focused on incident management using automation.
The first hands-on example was to auto-close an incident with no analyst interaction. We utilized the watchlist feature in Microsoft Sentinel, where we stored our allowed IP address and compared it with IPs involved in the incident. Based on the result, we auto-closed the incident or left a comment stating that the IP was not on the watchlist.
The second example expanded on the first example. As incidents can have more than one IP, we utilized an approval email action to ask analysts whether the incident should be auto-closed or whether a further investigation would be needed.
The final example used the automation rule to auto-close ...
Read now
Unlock full access