Retrieve Incident from Microsoft Sentinel and Trigger a Blink Workflow via Webhook

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Send a webhook request to a Blink workflow trigger whenever a new Incident is created in Microsoft Sentinel

Attribute Value
Type Playbook
Solution BlinkOps
Source View on GitHub

Additional Documentation

📄 Source: Sentinel-Incident-Handler/readme.md

Blink-Sentinel-Incident-Trigger

Summary

This playbook automatically triggers when a Microsoft Sentinel incident is created or updated, and sends a structured HTTPS POST request to Blink. The integration enables seamless coordination between Sentinel Incident and Blink automation workflows, allowing for rapid incident response, ticketing, notification dispatch, or any custom workflow configured in Blink.


Prerequisites

Before deploying this playbook, ensure the following prerequisites are completed:

  1. Create an Event-Based Workflow in Blink that is configured to trigger via webhook.

  1. Note down the following required value from Blink: - Blink Webhook Full URL – the full HTTPS endpoint URL to trigger your Blink workflow.


Deployment Instructions

To deploy the playbook into your Azure environment:

  1. Click the Deploy to Azure button below to launch the ARM Template deployment wizard.
  2. Provide the following required parameters: - Playbook-Name: Choose a clear and descriptive name for the Logic App (e.g., Blink_Sentinel_Incident_Trigger). - Blink-Webhook-Full-URL: Paste the full webhook URL from your Blink workflow.

Deploy to Azure
Deploy to Azure Gov


Post-Deployment Instructions

Once the playbook is deployed successfully, follow these steps to connect it with Microsoft Sentinel's automation rules:

1. Create Automation Rule for Incident Created

2. Create Automation Rule for Incident Updated


Support

For guidance on integrating Blink with other tools and services, visit the official Blink Documentation.



Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Playbooks · Back to BlinkOps