StratoSecure - Close Incident in Sentinel

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


When a StratoSecure finding is resolved or accepted, this playbook closes the corresponding Microsoft Sentinel incident as BenignPositive and writes an audit record to StratoSecure_PlaybookRuns_CL. Human approval is always required before the action executes.

Attribute Value
Type Playbook
Solution StratoSecure
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
StratoSecure_PlaybookRuns_CL ? ✓ ?

Logic App Connectors

This playbook uses 2 Logic App connectors / built-in actions:

Connector / Action Type Connections Actions
azureloganalyticsdatacollector Managed 1 1
azuresentinel Managed 1 1
Action parameters (URLs, paths, function IDs)

azureloganalyticsdatacollector (Managed)

Action Method Endpoint Other
Action_AuditLog post /api/logs —

azuresentinel (Managed)

Action Method Endpoint Other
Action_CloseIncident put /Incidents/subscriptions/@{triggerBody()?['workspaceInfo']?['SubscriptionId']}/resourceGroups/@{triggerBody()?['workspaceInfo']?['ResourceGroupName']}/providers/Microsoft.OperationalInsights/workspaces/@{parameters('WorkspaceName')}/providers/Microsoft.SecurityInsights/Incidents/@{triggerBody()?['object']?['name']}/close —

Additional Documentation

📄 Source: StratoSecure-CloseInSentinel/readme.md

StratoSecure — Close In Sentinel

Closes a Microsoft Sentinel incident after a StratoSecure finding is remediated or accepted. The incident is closed as BenignPositive - SuspiciousButExpected and an audit record is written to StratoSecure_PlaybookRuns_CL.

Prerequisites

Post-Deployment Steps

  1. Grant the Logic App system-assigned managed identity the Microsoft Sentinel Responder role on the Sentinel workspace.
  2. Configure the Sentinel automation rule to trigger this playbook when a finding is marked as remediated in StratoSecure.

Parameters

Parameter Type Description
PlaybookName string Logic App resource name
WorkspaceName string Microsoft Sentinel Log Analytics workspace name
LogAnalyticsWorkspaceId string Workspace ID for audit logging
LogAnalyticsWorkspaceKey securestring Workspace primary key for audit logging
RequireApproval bool When true, actions execute only after approval condition evaluates (default: true)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Playbooks · Back to StratoSecure