Azure-Sentinel icon indicating copy to clipboard operation
Azure-Sentinel copied to clipboard

RiskIQ Solution not authorizing during deployment

Open ml58158 opened this issue 3 years ago • 7 comments

Describe the bug When the RiskIQ solution is deployed to Sentinel , the API Connection does not automatically authorize which causes the playbooks to fail when ran.

To Reproduce Steps to reproduce the behavior:

  1. Deploy the RiskIQ solution from the ContentHub blade.
  2. Once fully deployed, run a riskiq playbook against an alert or incident with external facing data.
  3. Notice that the RiskIQ data does not populate in the comments section of the incident.
  4. Click on the logic app run results and look at the run details.
  5. Notice that connections fails with error: 401 unauthorized .

Next,

  1. Navigate to the Logic Apps section on Azure.
  2. Select one of the RiskIQ logic apps.
  3. Click on Api-Connections and select the api-connection named after the playbook.
  4. Click on Edit API connection
  5. Click on the blue Authorize button and authenticate .
  6. Click Save.
  7. Go back to the incident and rerun the playbook .
  8. Notice the playbook now runs successfully and comments the data in the incident. (Note this has to be for all 28 playbooks)

Expected behavior The expected behavior is the solution deploys and the playbooks run successfully . 2022-02-08 15_57_03-azuresentinel-RiskIQ-Intel-Summary-Domain-Alert-Trigger - Microsoft Azure - Work

ml58158 avatar Feb 08 '22 20:02 ml58158

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Feb 08 '22 20:02 github-actions[bot]

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Feb 09 '22 21:02 github-actions[bot]

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Mar 01 '22 14:03 github-actions[bot]

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Apr 25 '22 02:04 github-actions[bot]

@ml58158 : This seems to be a very old problem, and this solution may have already had numerous updates... Can you please check if this scenario is still valid? Thanks!!

v-rucdu avatar Jan 06 '23 10:01 v-rucdu

Hi @ml58158, We have added this information part of post deployment steps in our later releases. Hope this could fixed the issue. Let us know if you need any other details or suggestions. image Thanks

v-mchatla avatar Jan 11 '23 09:01 v-mchatla

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Jan 11 '23 10:01 github-actions[bot]

Since we have not received a response in the last 5 days, we are closing your issue #4132 as per our standard operating procedures. If you still need support for this issue, feel free to re-open at any time. Thank you for your co-operation.

v-amolpatil avatar Jan 31 '23 14:01 v-amolpatil

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Jan 31 '23 14:01 github-actions[bot]