StratoSecure - Create Jira Ticket

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


When a Microsoft Sentinel incident is created from a StratoSecure finding, this playbook opens a Jira bug ticket and writes an audit record to StratoSecure_PlaybookRuns_CL. Human approval is always required before the action executes.

Attribute Value
Type Playbook
Solution StratoSecure
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
StratoSecure_PlaybookRuns_CL ? ✓ ?

Logic App Connectors

This playbook uses 3 Logic App connectors / built-in actions:

Connector / Action Type Connections Actions
azureloganalyticsdatacollector Managed 1 1
azuresentinel Managed 1 0
http Built-in 0 1
Action parameters (URLs, paths, function IDs)

azureloganalyticsdatacollector (Managed)

Action Method Endpoint Other
Action_AuditLog post /api/logs —

http (Built-in)

Action Method Endpoint Other
Action_CreateJiraTicket POST [variables('HttpEndpoint')] —

Additional Documentation

📄 Source: StratoSecure-CreateJiraTicket/readme.md

StratoSecure — Create Jira Ticket

Creates a Jira bug ticket for each StratoSecure security finding incident triggered in Microsoft Sentinel. The ticket includes incident title, description, severity labels, and is tagged sentinel, stratosecure, and appsec.

Prerequisites

Post-Deployment Steps

  1. Grant the Logic App system-assigned managed identity the Microsoft Sentinel Responder role on the Sentinel workspace.
  2. Store the JiraApiToken in Azure Key Vault and reference it in the parameter.
  3. Verify the JiraProject key matches an existing project in your Jira instance.

Parameters

Parameter Type Description
PlaybookName string Logic App resource name
JiraBaseUrl string Jira instance base URL (e.g. https://your-org.atlassian.net)
JiraProject string Jira project key where tickets will be created (default: SEC)
JiraApiToken securestring Jira API token for authentication
JiraUserEmail string Email address associated with the Jira API token
LogAnalyticsWorkspaceId string Workspace ID for audit logging
LogAnalyticsWorkspaceKey securestring Workspace primary key for audit logging
RequireApproval bool When true, actions execute only after approval condition evaluates (default: true)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Playbooks · Back to StratoSecure