Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Leverages the Infoblox IQ for TD API to enrich a Microsoft Sentinel Incident triggered by an Infoblox IQ for TD Insight & ingest Insight details into custom InfobloxInsight tables using the Log Ingestion API. The tables are used to build the Infoblox IQ for TD Workbook. This playbook can be configured to run automatically when an incident occurs (recommended) or run on demand.
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | Infoblox |
| Source | View on GitHub |
This playbook uses 2 Logic App connectors / built-in actions:
| Connector / Action | Type | Connections | Actions |
|---|---|---|---|
azuresentinel |
Managed | 1 | 2 |
http |
Built-in | 0 | 10 |
azuresentinel (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Update_Incident_Tags | put | /Incidents |
— |
| Add_InfobloxInsightID_Tag | put | /Incidents |
— |
http (Built-in)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Get_Infoblox_Customer_Id | GET | https://csp.infoblox.com/api/atcfw/v1/account |
— |
| Get_Asset_Data | GET | https://csp.infoblox.com/api/v2/insights/@{items('For_each_Insight_ID')}/assets |
— |
| Send_Asset_Data | POST | @parameters('DCEIngestionEndpoint_Assets') |
— |
| Get_Indicator_Data | GET | https://csp.infoblox.com/api/v2/insights/@{items('For_each_Insight_ID')}/indicators |
— |
| Send_Indicator_Data | POST | @parameters('DCEIngestionEndpoint_Indicators') |
— |
| Get_Event_Data | GET | https://csp.infoblox.com/api/v2/insights/@{items('For_each_Insight_ID')}/events |
— |
| Send_Event_Data | POST | @parameters('DCEIngestionEndpoint_Events') |
— |
| Get_Insight_Data | GET | https://csp.infoblox.com/api/v2/insights/@{items('For_each_Insight_ID')} |
— |
| Send_Insight_Data_for_CDC | POST | @parameters('DCEIngestionEndpoint_Insight') |
— |
| Send_Insight_Data | POST | @parameters('DCEIngestionEndpoint_Insight') |
— |
This playbook uses the Infoblox IQ for TD Insights API to enrich a Microsoft Sentinel Incident triggered by an Infoblox IQ for TD Insight and ingest Insight details into the custom InfobloxInsight tables using the Log Ingestion API. These Incidents are triggered by the Infoblox - IQ for TD Insight Detected analytic queries packaged as part of this solution. These queries will read your data for insights and create an Incident when one is found, hereby known as a IQ for TD Insight Incident.
Then, you can run this playbook on those incidents to ingest many details about the Insight, placed in several custom tables prefixed with InfobloxInsight. This data also builds the Infoblox IQ for TD Insight Workbook you can use to richly visualize and drilldown your Insights.
It will also add several tags to the IQ for TD Insight Incident.
This playbook can be configured to run automatically when a IQ for TD Insight Incident occurs (recommended) or run on demand.

This playbook uses Managed Identity for authentication with the Log Ingestion API. The deployment automatically:
InfobloxInsight, InfobloxInsightAssets, InfobloxInsightIndicators and InfobloxInsightEvents tables in the Log Analytics WorkspaceAssign role to this playbook.
[Content truncated...]
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊