RecordedFuture-Alert-Importer

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


This playbook imports alerts from Recorded Future and stores them in a custom log (RecordedFuturePortalAlerts_CL) in the log analytics workspace. To create Microsoft Defender incidents from these alerts, use a Analytics Rule that queries the RecordedFuturePortalAlerts_CL table. Direct incident creation via Logic Apps is no longer supported in the unified Microsoft Defender portal.

Attribute Value
Type Playbook
Solution Recorded Future
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
RecordedFuturePortalAlerts_CL 🔶 ? ?

Logic App Connectors

This playbook uses 3 Logic App connectors / built-in actions:

Connector / Action Type Connections Actions
azureloganalyticsdatacollector Managed 1 1
azuremonitorlogs Managed 1 1
recordedfuturev2 Managed 1 1
Action parameters (URLs, paths, function IDs)

azureloganalyticsdatacollector (Managed)

Action Method Endpoint Other
Send_Data_2 post /api/logs

azuremonitorlogs (Managed)

Action Method Endpoint Other
Run_query_and_list_results post /queryData

recordedfuturev2 (Managed)

Action Method Endpoint Other
Search_Triggered_Alerts get /v2/alerts

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Playbooks · Back to Recorded Future