Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
This playbook restores the latest good Data Hawk (Helios) snapshot.
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | CohesitySecurity |
| Source | View on GitHub |
This playbook restores the latest good Data Hawk (Helios) snapshot. It’s recommended for running by Backup Admins only after they make sure that the existing data is compromised, and rollback to the previous snapshot, even at the expense of data loss, is really required. Please beware: It's operable only if you have installed the Function Apps and received some incidents that need an action on affected data.
Make sure the user that runs the playbook has the role Microsoft Sentinel Playbook Operator assigned. To assign the role, * Under the Subscriptions tab from the Home page, choose your subscription name. * Choose the Access Control (IAM) option from the left pane. * Click on Add > Add Role Assignment and add Microsoft Sentinel Playbook Operator to the user.
Authorize all connections * Go to Logic Apps and choose your playbook * In the Development Tools sections select API Connections. In the left pane you'll see the list of connections that you'll need to authorize * Authorize the Azure blob storage connection by selecting it and clicking on General\Edit API Connection
Grant KeyVault permissions to your playbook * Go to Key vaults and choose your keyvault, which starts from cohesitypro and is followed by a sequence of letters and numbers, e.g. cohesityprofnxj32cucakwk. * On the right pane, select Access Policies and click +Create. * Choose Get permission in the Secret Permissions section and press Next. * Enter your playbook name and press Next. * Press Next and then Create to finish granting permissions.
(Recommendation) Limit access rights to this playbook to only Backup Admins because this playbook rolls back customer data that can result in a loss of important data if used without a good reason. * From the Microsoft Sentinel navigation menu, select Settings. * In the Settings blade, select the Settings tab and expand Playbook Permissions. * Select Configure Permissions to open the Manage Permissions panel. * Select the required resource group and click Apply. * Select Done.
[Content truncated...]
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊