Abnormal Security - Add Incident Comment

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


This playbook is triggered when a Microsoft Sentinel incident is created. It adds a comment to the incident summarizing the Abnormal Security alert (provider, severity, alert product names, and a link to the incident) so analysts have Abnormal context inline. It uses only the Microsoft Sentinel connector and requires no third-party credentials.

Attribute Value
Type Playbook
Solution AbnormalSecurity
Source View on GitHub

Logic App Connectors

This playbook uses 1 Logic App connector / built-in action:

Connector / Action Type Connections Actions
azuresentinel Managed 1 1
Action parameters (URLs, paths, function IDs)

azuresentinel (Managed)

Action Method Endpoint Other
Add_comment_to_incident_(V3) post /Incidents/Comment

Additional Documentation

📄 Source: AbnormalSecurity-AddIncidentComment/readme.md

This playbook is triggered when a Microsoft Sentinel incident is created. It adds a comment to the incident summarizing the Abnormal Security alert (provider, severity, title) so analysts have Abnormal context inline.

It uses only the Microsoft Sentinel connector with a system-assigned managed identity and requires no third-party credentials.

Quick Deployment

After deployment:

  1. Assign the Microsoft Sentinel Responder role to the playbook's managed identity on the resource group or workspace.
  2. Create an Automation Rule that runs this playbook on incidents created by the Abnormal Security analytic rules.

Prerequisites

None beyond a Microsoft Sentinel-enabled Log Analytics workspace and the role assignment above.


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Playbooks · Back to AbnormalSecurity