Close Cohesity Helios Incident

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


This playbook closes the corresponding Cohesity DataHawk (Helios) ticket.

Attribute Value
Type Playbook
Solution CohesitySecurity
Source View on GitHub

Logic App Connectors

This playbook uses 3 Logic App connectors / built-in actions:

Connector / Action Type Connections Actions
azuresentinel Managed 1 0
keyvault Managed 1 1
http Built-in 0 1
Action parameters (URLs, paths, function IDs)

keyvault (Managed)

Action Method Endpoint Other
Get_secret get /secrets/@{encodeURIComponent('ApiKey')}/value

http (Built-in)

Action Method Endpoint Other
HTTP PUT https://helios.cohesity.com/v2/mcm/alert-service/alerts/@{variables('helioID')}/state

Additional Documentation

📄 Source: Cohesity_Close_Helios_Incident/readme.md

Cohesity Close Helios Incident Playbook

Summary

This playbook closes the Cohesity Data Cloud alert. Remember: It works only if you have installed the Function Apps and have received a few incidents that require closure.

Deployment Instructions

  1. Click on the "Deploy to Azure" button to deploy the playbook. This step directs you to deploy an ARM Template wizard. Deploy to Azure
  2. Fill the required parameters:

Post-deployment Instructions

  1. The user who runs the playbook must have the role Microsoft Sentinel Playbook Operator. To assign the role:
  1. Grant KeyVault permissions to your playbook. Follow the steps below.

Troubleshooting

  1. If your API key expired, then you have to replace it with a new one.
  1. If you see the Forbidden error message in the Keyvault block when you run the playbook, you can authorize it manually.

References


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Playbooks · Back to CohesitySecurity