Overview of the Microsoft Sentinel connector
While there are many logic app connectors, and more are being added all the time, the one we are concerned with is the Microsoft Sentinel connector. It provides us with the triggers that can kick off our playbook. It also contains various actions that can perform tasks such as obtaining information about a specific incident, getting information about the entities associated with an alert, updating an incident, and more.
Note
At the time of writing, all the features of the Microsoft Sentinel connector were in preview, so they could have changed from what is shown and discussed here.
As discussed in the previous section, the connector currently has two triggers called When a response to an Microsoft Sentinel alert is triggered and When Microsoft Sentinel incident creation rule was triggered. This means that the trigger will fire whenever an alert or incident is created, depending on which one is selected.
It is worth noting that...