Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
This playbook is triggered manually from a Domain Monitor Tab from Cyjax Workbook in Microsoft Sentinel. It fetches domain monitor data from Cyjax based on user provided inputs (Since, Until and Query) and display them in the workbook panel.
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | Cyjax |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
CyjaxDomainMonitor_CL 🔶 |
? | ✓ | ? |
📄 Source: CyjaxDomainMonitor/readme.md
This playbook is triggered manually from the Domain Monitor tab in the Cyjax Workbook within Microsoft Sentinel. It fetches domain monitoring data from the Cyjax API based on user-provided inputs (Since, Until, and Query) and displays the results in the workbook panel. This playbook helps you monitor and investigate domain-related threat intelligence.
Once deployment is complete, authorize each connection. 1. Go to your logic app → API connections → Select Keyvault connection resource. 2. Go to General → edit API connection. 3. Click Authorize. 4. Sign in. 5. Click Save. 6. Repeat steps for Log Analytics Data Collector connection.
Add access policy for the playbook's managed identity to read secrets from Key Vault. 1. Go to logic app → your logic app → identity → System assigned Managed identity and copy Object (principal) ID. 2. Go to keyvaults → your keyvault → Access policies → create. 3. Select Get and List permissions for Secrets. Click next. 4. In the principal section, search by copied object ID. Click next. 5. Click review + create.
Configure the Cyjax workbook to call this playbook with the HTTP POST URL. 1. Go to Logic App → your Logic App → Logic app designer. 2. Copy the HTTP POST URL from the trigger. 3. Configure the Cyjax workbook Domain Monitor tab to use this URL for querying domain monitoring data.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊