Vectra Close Detections On Incident Close
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
↑ Back to Content Index
This playbook is triggered when a Microsoft Sentinel incident is closed. It reads Vectra detection_id values from incident alert Custom Details, maps the Microsoft Sentinel close classification to a Vectra close reason (remediated or benign), and bulk-closes all detections via the Vectra PATCH /api/v3.5/detections/close endpoint. Authentication is handled via the VectraGenerateAccessToken playbook.
Logic App Connectors
This playbook uses 4 Logic App connectors / built-in actions:
Action parameters (URLs, paths, function IDs)
| Action |
Method |
Endpoint |
Other |
| Add_comment_to_incident_(V3) |
post |
/Incidents/Comment |
— |
| Add_comment_to_incident_(V3)_-_No_Detections_Found |
post |
/Incidents/Comment |
— |
| Action |
Method |
Endpoint |
Other |
| Get_Access_Token_For_Closing_Detections |
get |
/secrets/@{encodeURIComponent('Vectra-Access-Token')}/value |
— |
http (Built-in)
| Action |
Method |
Endpoint |
Other |
| HTTP_Request_To_Close_Detections |
PATCH |
@{variables('base_url')}/api/@{variables('api_version')}/detections/close |
— |
| Action |
Method |
Endpoint |
Other |
| GenerateAccessTokenVectra |
— |
— |
workflowId=[concat('/subscriptions/', subscription().subscriptionId, '/resourceGroups/',resourceGroup().name,'/providers/Microsoft.Logic/workflows/',trim(parameters('GenerateAccessCredPlaybookName')))] triggerName=manual |
Additional Documentation
📄 Source: VectraCloseDetectionsOnIncidentClose/readme.md
Summary
This playbook is triggered when a Microsoft Sentinel incident is closed. It reads Vectra detection_id values from the incident alert Custom Details, maps the Microsoft Sentinel close classification to a Vectra close reason (remediated or benign), and bulk-closes all detections via the Vectra PATCH /api/v3.5/detections/close endpoint. Authentication is handled via the VectraGenerateAccessToken playbook.
Prerequisites
- The Vectra XDR data connector should be configured to create alerts and generate an incident based on entity data in Microsoft Sentinel.
- Obtain Key Vault name and Tenant ID where client credentials are stored using which access token will be generated.
- Create a Key Vault with a unique name.
- Go to Key Vaults → your Key Vault → Overview and copy Directory ID, which will be used as the tenant ID.
- NOTE: Ensure the Permission model in the Access Configuration of Key Vault is set to 'Vault access policy'.
- Ensure the VectraGenerateAccessToken playbook is deployed before deploying VectraCloseDetectionsOnIncidentClose playbook.
- The Sentinel Analytics Rule that creates incidents must populate alert Custom Details with the key 'detection_id'.
- A Sentinel Automation Rule configured to run this playbook when the incident status changes to Closed.
Deployment Instructions
- To deploy the Playbook, click the Deploy to Azure button. This will launch the ARM Template deployment wizard.
- Fill in the required parameters:
- PlaybookName: Enter the playbook name here.
- KeyVaultName: Name of the Key Vault where secrets are stored.
- TenantId: Tenant ID where the Key Vault is located.
- BaseURL: Enter the base URL of your Vectra account.
- GenerateAccessCredPlaybookName: Playbook name which is deployed as part of prerequisites.

Post-Deployment Instructions
a. Authorize connections
Once deployment is complete, authorize each connection.
- Go to your logic app → API connections → Select keyvault connection resource.
- Go to General → Edit API connection.
- Click Authorize.
- Sign in.
- Click Save.
- Repeat steps for other connections.
b. Add Access Policy in Key Vault
Add access policy for the playbook's managed identity and authorized user to read and write secrets of the Key Vault.
- Go to Logic App → your Logic App → Identity → System assigned Managed identity and copy Object (principal) ID.
- Go to Key Vaults → your Key Vault → Access policies → Create.
- Select all keys & secrets permissions. Click Next.
- In the principal section, search by copied Object ID. Click Next.
- Click Review + Create.
- Repeat steps 2 to 5 to add access policy for the user account used to authorize the connection.
c. Assign Role to update incident
After authorizing each connection, assign role to this playbook.
- Go to Log Analytics Workspace → your workspace → Access Control → Add.
- Add role assignment.
- Assignment type: Job function roles.
- Role: Microsoft Sentinel Responder.
- Members: select managed identity for assigned access to and add your logic app as member.
- Click on review+assign.
d. Configurations in Microsoft Sentinel
- In Microsoft Sentinel, create an Automation Rule: Trigger = 'When an incident is updated', Condition = 'Status changed to Closed', Action = 'Run playbook' and select this playbook.
- The analytical rule that creates incidents must populate alert Custom Details with the key 'detection_id'. Incident should have Entity mapping.
e. Note
- The playbook reads Vectra
detection_id values from the incident alert Custom Details (key 'detection_id') and closes all of the referenced detections when the incident is closed.
- The playbook runs only when the incident status is Closed.
- The Microsoft Sentinel close classification is mapped to the Vectra close reason as follows:
- TruePositive → remediated
- Any other classification (BenignPositive, FalsePositive, Undetermined, or none) → benign (default)
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
↑ Back to Playbooks · Back to Vectra XDR