You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/platform-services/automation-service/app-central/integrations/microsoft-sentinel.md
+12-11Lines changed: 12 additions & 11 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -15,14 +15,14 @@ Microsoft Sentinel is a cloud-native security information and event manager (SIE
15
15
16
16
### Purpose
17
17
18
-
This documentation outlines the Microsoft Sentinel integration, providing details on its capabilities, usage, and support for managing security incidents and automating responses within Microsoft Sentinel.
18
+
This documentation outlines the Microsoft Sentinel integration, providing details on its capabilities, usage, and support for managing security incidents.
19
19
20
20
### Use cases
21
21
22
22
* Automatically fetch and process security incidents from Sentinel.
23
-
*Enrich incidents with contextual data from third-party sources.
24
-
* Trigger automated containment actions such as disabling users or isolating machines.
25
-
*Provide a unified security operations view through integration with external systems.
23
+
*Review incident details, comments, and related entities to streamline triage.
24
+
* Trigger automated incident management workflows, such as updating incident status, severity, or ownership using Update Incident, or adding context through Add Incident Comment.
25
+
*Remove false positives or resolved alerts by leveraging the Delete Incident action.
26
26
27
27
### Supported Versions
28
28
@@ -94,13 +94,14 @@ For information about Microsoft Sentinel, see [Microsoft Sentinel documentation]
0 commit comments