Summary
In this chapter, you learned how to create a playbook that you can use in your analytic query rules to perform SOAR actions. Playbooks are based on Azure Logic Apps, with the only difference being that the Microsoft Sentinel connector must be used for a Logic App to be a playbook.
With what you have learned, you can now create playbooks to automate a lot of actions that had to be performed manually previously. You read about one such example, but there is no limit to what you can do!
In the next chapter, we will use what we learned in this chapter to build a playbook that will create a new ServiceNow ticket and update the incident with the ticket number.