Introduction to Microsoft Sentinel Automation
When Microsoft Sentinel was first released, each playbook had to be assigned to each analytic rule individually and all actions required the use of a playbook. Microsoft Sentinel Automation was introduced to make using playbooks much easier, while, at the same time, allowing a user to perform actions, including changing an incident's severity, without needing to write a playbook.
Note
When this chapter was being written, the Automation features were in preview, so some features may have changed.
Let's start by looking at the Automation page. To access this page, select the Automation navigation menu entry from the Microsoft Sentinel navigation pane. The Automation screen will be displayed, as shown in the following screenshot:
We shall look at each part of this page in the following sections.
The header bar
The header bar, as...