Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
This playbook updates the status of all detections listed in an incident's custom details based on the current incident status. When the incident is Active, detections are set to 'acknowledged'. When the incident is Closed, detections are closed with a reason derived from the incident close classification (True Positive → remediated; Benign Positive / False Positive / Undetermined → benign).
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | Vectra XDR |
| Source | View on GitHub |
This playbook uses 4 Logic App connectors / built-in actions:
| Connector / Action | Type | Connections | Actions |
|---|---|---|---|
azuresentinel |
Managed | 1 | 1 |
keyvault |
Managed | 1 | 2 |
http |
Built-in | 0 | 2 |
workflow |
Built-in | 0 | 2 |
azuresentinel (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Add_Comment_To_Incident | post | /Incidents/Comment |
— |
keyvault (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Get_Access_Token_For_Close_Detections | get | /secrets/@{encodeURIComponent('Vectra-Access-Token')}/value |
— |
| Get_Access_Token_For_Acknowledge_Detections | get | /secrets/@{encodeURIComponent('Vectra-Access-Token')}/value |
— |
http (Built-in)| Action | Method | Endpoint | Other |
|---|---|---|---|
| HTTP_Request_To_Close_Detections | PATCH | @{variables('base_url')}/api/@{variables('api_version')}/detections/close |
— |
| HTTP_Request_To_Acknowledge_Detections | PATCH | @{variables('base_url')}/api/@{variables('api_version')}/detections/ |
— |
workflow (Built-in)| Action | Method | Endpoint | Other |
|---|---|---|---|
| GenerateAccessTokenVectra_For_Close_Detections | — | — | workflowId=[concat('/subscriptions/', subscription().subscriptionId, '/resourceGroups/', resourceGroup().name, '/providers/Microsoft.Logic/workflows/', trim(parameters('GenerateAccessCredPlaybookName')))]triggerName= manual |
| GenerateAccessTokenVectra_For_Acknowledge_Detections | — | — | workflowId=[concat('/subscriptions/', subscription().subscriptionId, '/resourceGroups/', resourceGroup().name, '/providers/Microsoft.Logic/workflows/', trim(parameters('GenerateAccessCredPlaybookName')))]triggerName= manual |
📄 Source: VectraSetDetectionStatus/readme.md
This playbook automatically updates the status of all detections listed in an incident's custom details based on the current incident status. When an incident is marked as Active, detections are set to 'acknowledged'. When an incident is Closed, detections are closed with a reason derived from the incident classification (True Positive → remediated; Benign Positive / False Positive / Undetermined → benign).
Once deployment is complete, authorize each connection.
Add access policy for the playbook's managed identity and authorized user to read and write secrets of the Key Vault.
After authorizing each connection, assign role to this playbook.
detection_id populated in Custom Details.The playbook uses the following mappings to update detection status:
| Incident Status | Detection Status | Close Reason (if Closed) |
|---|---|---|
| Active | acknowledged | N/A |
| Closed (True Positive) | closed | remediated |
| Closed (Benign Positive) | closed | benign |
| Closed (False Positive) | closed | benign |
| Closed (Undetermined) | closed | benign |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊