Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
When a Microsoft Sentinel incident is created from a StratoSecure finding, this playbook calls the StratoSecure API to assign the finding to the SOC team and writes an audit record to StratoSecure_PlaybookRuns_CL. Human approval is always required before the action executes.
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | StratoSecure |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
StratoSecure_PlaybookRuns_CL |
? | ✓ | ? |
This playbook uses 3 Logic App connectors / built-in actions:
| Connector / Action | Type | Connections | Actions |
|---|---|---|---|
azureloganalyticsdatacollector |
Managed | 1 | 1 |
azuresentinel |
Managed | 1 | 0 |
http |
Built-in | 0 | 1 |
azureloganalyticsdatacollector (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Action_AuditLog | post | /api/logs |
— |
http (Built-in)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Action_AssignOwner | PATCH | [variables('HttpEndpoint')] |
— |
📄 Source: StratoSecure-AssignOwner/readme.md
Assigns a finding owner in StratoSecure based on incident triage in Microsoft Sentinel. When an incident is created, this playbook calls the StratoSecure API to assign the finding to the SOC team and writes an audit record to StratoSecure_PlaybookRuns_CL.
StratoApiKey in Azure Key Vault and reference it in the parameter.| Parameter | Type | Description |
|---|---|---|
| PlaybookName | string | Logic App resource name |
| StratoApiBaseUrl | string | StratoSecure platform API base URL (default: https://api.stratocode.io) |
| StratoApiKey | securestring | StratoSecure API key |
| LogAnalyticsWorkspaceId | string | Workspace ID for audit logging |
| LogAnalyticsWorkspaceKey | securestring | Workspace primary key for audit logging |
| RequireApproval | bool | When true, actions execute only after approval condition evaluates (default: true) |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊