Azure-Sentinel icon indicating copy to clipboard operation
Azure-Sentinel copied to clipboard

Created a new tool for creating Incidents with email

Open samikroy opened this issue 3 years ago • 33 comments

A detailed explanation is here. https://github.com/samikroy/Azure-Sentinel/blob/patch-32/Tools/Create%20Incidents%20with%20Email/Readme.md

This will be a part of the readme after the PR merge.

samikroy avatar Oct 17 '22 14:10 samikroy

@v-mchatla - Request your help for the approval.

samikroy avatar Oct 17 '22 14:10 samikroy

@rushriva : Please have a look and provide an update. Thanks!

v-spadarthi avatar Oct 21 '22 05:10 v-spadarthi

@rushriva : Please have a look and provide an update. Thanks!

v-spadarthi avatar Oct 25 '22 08:10 v-spadarthi

@rushriva : Please have a look and provide an update. Thanks!

v-spadarthi avatar Oct 28 '22 05:10 v-spadarthi

@rushriva is checking with @shainw.

v-spadarthi avatar Oct 31 '22 06:10 v-spadarthi

@rushriva : Please have a look and provide an update. Thanks!

v-spadarthi avatar Nov 02 '22 01:11 v-spadarthi

@rushriva : Please have a look and provide an update. Thanks!

v-spadarthi avatar Nov 04 '22 02:11 v-spadarthi

@rushriva : Please have a look and provide an update. Thanks!

v-spadarthi avatar Nov 08 '22 07:11 v-spadarthi

@rushriva : Please have a look and provide an update. Thanks!

v-spadarthi avatar Nov 11 '22 05:11 v-spadarthi

@rushriva : Please have a look and provide an update. Thanks!

v-spadarthi avatar Nov 14 '22 05:11 v-spadarthi

@rushriva : Please have a look and provide an update. Thanks!

v-spadarthi avatar Nov 16 '22 04:11 v-spadarthi

@rushriva : Please have a look and provide an update. Thanks!

v-spadarthi avatar Nov 18 '22 04:11 v-spadarthi

@rushriva : Please have a look and provide an update. Thanks!

v-spadarthi avatar Nov 23 '22 04:11 v-spadarthi

@rushriva : Please have a look and provide an update. Thanks!

v-spadarthi avatar Nov 25 '22 03:11 v-spadarthi

Hi @samikroy -

Thank you for this content. Based on the functionality I see this is automation playbook and can we move this to Playbook folder, so that we can get into Content hub subsequently. While moving, can you please add following elements, so that it will be ready for content hub

  1. Metadata section:
  • You can find the instructions here - https://github.com/Azure/Azure-Sentinel/tree/master/docs/New%20Playbooks%20Contribution%20Guide#contribution-guidelines
  • For examples you can refer this playbook https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Okta%20Single%20Sign-On/Playbooks/OktaPlaybooks/Okta-EnrichIncidentWithUserDetails/azuredeploy.json
  1. As a best practice, we recommend sentinel connection in playbooks uses "ManagedSecurityIdentity". Please refer Sample Template for sample template. For more details, refer this. Make sure to do changes at 3 places

image

image

image

anki-narravula avatar Nov 25 '22 07:11 anki-narravula

@samikroy : Please address the @anki-narravula comments.

v-spadarthi avatar Nov 28 '22 05:11 v-spadarthi

@anki-narravula @v-spadarthi - Please have a look at the updated code and share your reviews !

samikroy avatar Nov 29 '22 19:11 samikroy

@anki-narravula : Please have a look and provide your feedback @samikroy addressed your comments.

v-spadarthi avatar Dec 02 '22 04:12 v-spadarthi

@anki-narravula @v-spadarthi - Please have a look at the updated code and share your reviews !

@samikroy Metadata object is still missing, example one

image

anki-narravula avatar Dec 06 '22 10:12 anki-narravula

@samikroy : Please address the @anki-narravula comments.

v-spadarthi avatar Dec 08 '22 11:12 v-spadarthi

@samikroy : Please address the @anki-narravula comments.

v-spadarthi avatar Dec 13 '22 06:12 v-spadarthi

hi @samikroy, Please add metadata object to your playbook, so that @anki-narravula can review and merge your changes. Thanks

v-mchatla avatar Dec 15 '22 05:12 v-mchatla

@v-mchatla - Could you please help with the merge.

samikroy avatar Dec 19 '22 16:12 samikroy

@anki-narravula , @v-spadarthi & @v-mchatla - Could you please help with the merge as the comments are addressed now.

samikroy avatar Dec 21 '22 14:12 samikroy

Hi @anki-narravula, Author has addressed your comments. Can you please review and provide your approval. Thanks

v-mchatla avatar Dec 21 '22 14:12 v-mchatla

@v-mchatla , @anki-narravula, @v-spadarthi - Could you please help with the merge.

samikroy avatar Dec 26 '22 11:12 samikroy

Hi @samikroy -

Thank you for this content. Based on the functionality I see this is automation playbook and can we move this to Playbook folder, so that we can get into Content hub subsequently. While moving, can you please add following elements, so that it will be ready for content hub

  1. Metadata section:
  • You can find the instructions here - https://github.com/Azure/Azure-Sentinel/tree/master/docs/New%20Playbooks%20Contribution%20Guide#contribution-guidelines
  • For examples you can refer this playbook https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Okta%20Single%20Sign-On/Playbooks/OktaPlaybooks/Okta-EnrichIncidentWithUserDetails/azuredeploy.json
  1. As a best practice, we recommend sentinel connection in playbooks uses "ManagedSecurityIdentity". Please refer Sample Template for sample template. For more details, refer this. Make sure to do changes at 3 places

image

image

image

@samikroy , did you checked the 2-point mentioned by anki , regarding "managedserviceidentity" , As i am not able to see the changes being done,

Kindly check again

manishkumar1991 avatar Dec 26 '22 11:12 manishkumar1991

@samikroy: Please address the @manishkumar1991 comments. Thanks!

v-spadarthi avatar Dec 27 '22 09:12 v-spadarthi

@samikroy: Please address the @manishkumar1991 comments. Thanks!

v-spadarthi avatar Dec 29 '22 09:12 v-spadarthi

@samikroy: Please address the @manishkumar1991 comments. Thanks!

v-spadarthi avatar Jan 03 '23 08:01 v-spadarthi