Notify When Incident Is Reopened
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
↑ Back to Content Index
This playbook is utilizing new update trigger to notify person/group on Microsoft Teams/Outlook when incident is reopened.
Additional Documentation
📄 Source: Notify-IncidentReopened/readme.md
Notify-IncidentReopened
author: Benjamin Kovacevic
This playbook is utilizing new update trigger to notify person/group on Microsoft Teams/Outlook when incident is reopened.
Prerequisites
- Email address to where notification will be sent to.
- Microsoft Teams Team ID and Channel ID (Instructions to get IDs - https://www.linkedin.com/pulse/3-ways-locate-microsoft-team-id-christopher-barber-/) or choose Team and Channel after the deployment
Quick Deployment
Post-deployment
- Authorize Microsoft Teams and Microsoft Office 365 Outlook connectors
- Choose Microsoft Teams Team and Channel where to send the adaptive card (only if Team ID and Channel ID were not added during the deployment)
- Add playbook as an action to the automation rule
- Trigger = When incident is updated;
- Condition = Staus > Changed From > Closed;.
Automation rule example

- If you want to receive notifications only on Microsoft Teams or only on Microsoft Office 365 Outlook, please remove unneeded connection. To remove, click on 3 dots on top right side of connector, and choose "Delete".
Delete connection example

Screenshots
Playbook


Teams

Outlook

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
↑ Back to Playbooks · Back to SentinelSOARessentials