Creating and using automation rules to manage responses
Automation rules in Microsoft Sentinel are used to manage and orchestrate responses to threats. They can be set using triggers and actions, such as when an incident is created. In this case, this would be the trigger, and running a playbook in response would be the action. To create an automation rule, complete the following steps:
- In Microsoft Sentinel, navigate to Automation | Create | Automation rule. The Create new automation rule panel will open as shown here:
Figure 9.47: Configuring an automation rule
- Set a name for your rule and select a trigger action based on incident creation, incident update, or alert creation. Add any required conditions (for more information on this, refer to the Further reading section at the end of this chapter), and then select the action you wish to perform when there is a match. The available actions are as follows:
- Run playbook
- Change status...