Cohesity Incident Email

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


This playbook sends an email to the recipient with the details related to the incidents.

Attribute Value
Type Playbook
Solution CohesitySecurity
Source View on GitHub

Logic App Connectors

This playbook uses 2 Logic App connectors / built-in actions:

Connector / Action Type Connections Actions
azuresentinel Managed 1 0
outlook Managed 1 1
Action parameters (URLs, paths, function IDs)

outlook (Managed)

Action Method Endpoint Other
Send_email_(V2) post /v2/Mail

Additional Documentation

📄 Source: Cohesity_Send_Incident_Email/readme.md

Summary

This playbook sends an email to the recipient with the incident details..

Prerequisites

  1. Create a distribution list (email) that will be used for sending out incident notifications.

Deployment instructions

  1. Deploy the playbook by clicking on the "Deploy to Azure" button. This will take you to deploying an ARM Template wizard. Deploy to Azure
  2. Fill in the required parameters:

Post-Deployment instructions

  1. Make sure the user that runs the playbook has the role Microsoft Sentinel Playbook Operator assigned. To assign the role,
  1. To enable this playbook, you need authorize Outlook connection (details)

Alternatively, you can follow these steps to achieve the same goal. This would be especially useful if the previous steps didn’t work for you.

Troubleshooting

To change the email address in the playbook:

References


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Playbooks · Back to CohesitySecurity