96abda46d5 | ||
---|---|---|
.. | ||
incident-trigger | ||
readme.md |
readme.md
Send Slack Message Via Webhook
author: Zachi Neuman
This playbook will be sending slack with basic incidents details (Incident title, severity, tactics, link,…) when incident is created in Azure Sentinel. The playbook includes functionality to:
- Close Incident As False Positive
- Close Incident As Benign Positve
- Change Incident Status To Active
- White List Entities
Pre-requisites:
Slack application with:
- Webhook installed 1.1 How to install webhook - https://api.slack.com/messaging/webhooks
- Interactivity Enbaled
Deployment:
[![Deploy to Azure Gov](https://aka.ms/deploytoazuregovbutton)]()Post-deployment
Configure connections
Edit the Logic App or go to Logic app designer.
Attach the playbook
After deployment, attach this playbook to an automation rule so it runs when the incident is created.
Learn more about automation rules