Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Azure_Sentinel_Logo.pngImage Added

What does the integration offer?

...

To configure the integration of Microsoft Sentinel with Compass, complete the following steps:

  1. Create a logic app using Azure Deploy Template.

  2. Enter values for Subscription and Resource Group.

  3. Enter a name in Logic App Name.

  4. Paste the URL previously copied from Compass into Endpoint.

  5. Select Review + create.

  6. Select Create.

  7. Go to the API Connection resource created from the template.

  8. Select General and then Edit API connection.

  9. Authorize the connection and select Save.

  10. Go to the Sentinel workspace. Under Configuration, select Automation.

  11. Select Create and then Automation Rule.

  12. Under Actions, select Run Playbook and select the logic app created from the template.

  13. Select Apply.

  14. Create a second automation rule.

  15. For Trigger, select When incident is updated .

  16. Add a new condition. Select Condition and then Condition (And) with the field Status Changed.

  17. Select Apply.

...