Introduction to Microsoft Sentinel playbooks
Microsoft Sentinel uses Azure Logic Apps for its workflow automation. An Microsoft Sentinel playbook is a logic app that uses the Microsoft Sentinel connector to trigger the workflow. As we go through this chapter, many of the screenshots we will be looking at will be logic app pages, which reinforces this concept. The full extent of how to use Logic Apps is beyond the scope of this book, so we will just cover the Microsoft Sentinel connector, which contains logic app triggers and actions for Microsoft Sentinel.
Note
For this chapter, the terms playbook and logic app will be used interchangeably. For more information on Azure Logic Apps, go to https://azure.microsoft.com/en-us/services/logic-apps/.
Logic apps use connectors (not to be confused with Microsoft Sentinel data connectors) and actions to perform a workflow's activities. A logic app connector provides access to events and data. Actions will perform a specific task...