The Hive - Create alert
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
↑ Back to Content Index
Once a new Microsoft Sentinel incident is created, this playbook gets triggered and performs the following actions: 1. Parses alert extended properties. 2. Parses alert custom details. 3. Creates alert in TheHive with description, source, sourceRef, title and type passed.
Additional Documentation
📄 Source: TheHive-CreateAlert/readme.md
TheHive-CreateAlert
Summary
When a new sentinel alerts is created, this playbook gets triggered and performs the following actions:
- Parse alert extended properties
- Parse alert custom details
- Creates alert in TheHive with description, source, sourceRef, title and type passed.

Prerequisites
- Prior to the deployment of this playbook, TheHive API Connector needs to be deployed under the same subscription.
- Obtain TheHive API credentials. Refer to TheHive API Custom Connector documentation.
Deployment instructions
- To deploy the Playbook, click the Deploy to Azure button. This will launch the ARM Template deployment wizard.
- Fill in the required paramteres:
- Playbook Name: Enter the playbook name here
- Connector Name: Enter the Logic App connector name for TheHive here
- onPremiseGatewayName: Provide the On-premises data gateway that will be used with The Hive connector. Data gateway should be deployed under the same subscription and resource group as playbook.

Post-Deployment instructions
a. Authorize connections
Once deployment is complete, authorize each connection.
- Click the Microsoft Sentinel connection resource
- Click edit API connection
- Click Authorize
- Sign in
- Click Save
- Repeat steps for other connections
b. Configurations in Sentinel
- In Microsoft Sentinel, analytical rules should be configured to trigger an alert. An alert should contain source and sourceRef custom entities. Docomentation about custom entities values
- Configure the automation rules to trigger the playbook.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
↑ Back to Playbooks · Back to TheHive