Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Leverages the Infoblox IQ for Threat Defense Insights API to take action on an Insight by applying the provided recommendation, then ingests the updated Insight details into the custom InfobloxInsight table. This playbook is triggered on demand with an insight_id and recommendation_id.
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | Infoblox |
| Source | View on GitHub |
This playbook uses 1 Logic App connector / built-in action:
| Connector / Action | Type | Connections | Actions |
|---|---|---|---|
http |
Built-in | 0 | 4 |
http (Built-in)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Get_Infoblox_Customer_Id | GET | https://csp.infoblox.com/api/atcfw/v1/account |
— |
| Take_Action_on_Insight | POST | https://csp.infoblox.com/api/v2/insights/@{triggerBody()?['insight_id']}/actions |
— |
| Get_Insight_Data | GET | https://csp.infoblox.com/api/v2/insights/@{triggerBody()?['insight_id']} |
— |
| Send_Insight_Data | POST | @parameters('DCEIngestionEndpoint') |
— |
This playbook leverages the Infoblox IQ for Threat Defense Insights API to take action on an Insight by applying a provided recommendation. After the action is applied, it fetches the updated Insight details and ingests them into the custom InfobloxInsight table using the Log Ingestion API.
The playbook is triggered on demand with an insight_id and a recommendation_id. It first resolves your Infoblox customer ID, submits the recommendation against the Insight, validates that the action succeeded, and then re-ingests the refreshed Insight data so your InfobloxInsight table (and the Infoblox SOC Insight Workbook) reflect the latest state. If the action cannot be applied, the playbook terminates with a failure and surfaces the reason returned by the API.

InfobloxInsight table will be created.InfobloxInsight table will be createdThis playbook uses Managed Identity for authentication with the Log Ingestion API. The deployment automatically:
InfobloxInsight table in the Log Analytics WorkspaceBrowse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊