Azure-Sentinel/Playbooks/Get-GeoFromIpAndTagIncident
dicolanl 2852a71a55 Fixing Playbook Deploy URLs 2020-02-24 10:06:59 -05:00
..
azuredeploy.json v2 2019-12-07 12:37:50 -08:00
readme.md Fixing Playbook Deploy URLs 2020-02-24 10:06:59 -05:00

readme.md

Get-GeoFromIpAndTagIncident

author: Nicholas DiCola

This playbook will take the IP address entities from the Incident and query a Geo-IP API to geo-locate the IP Address. It will write the City and Country to a tag on the Incident.