Azure-Sentinel/Playbooks/AzureMonitor-ManagedId
..
azuredeploy.json
azuremonitor.liquid
readme.md

readme.md

AzureMonitor-ManagedId

This playbook is an equivalent of AzureMonitor KQL query base block but allowing to use Managed Identity with HTTP request block. Credits to @koosg for initial work.

Prerequisite:

  • Create Azure Integration account in same region than targeted logic app and load the liquid map as name 'azuremonitor'. (manual only at this point)
  • Make role assignment "Log Analytics Reader" to managed identity for appropriate scope (target log analytics).

Deploy to Azure

Deploy to Azure Deploy to Azure Gov

References