Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
This playbook leverages Illumio workloads API to enrich IP, Hostname and Labels, found in Microsoft Sentinel alerts.
.
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | IllumioSaaS |
| Source | View on GitHub |
📄 Source: Illumio-Get-Ven-Details/readme.md
Playbooks are collections of procedures that can be run from Microsoft Sentinel.
This playbook can be configured to respond to Microsoft Sentinel alerts.
Deploy the function app first:
This playbook creates API connections, since it needs to query/interact with Outlook 365 and Microsoft Sentinel.
Hence, ensure to provide "Deployers User name" as an email address.
Provide PCE fqdn, port, org id, api key and secret, click Next and follow next steps to deploy playbook.
Once deployed, authorize the api connections.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊