Microsoft Sentinel automation rules to manage response | Logic Apps | Automation Rules | Playbooks

Поделиться
HTML-код
  • Опубликовано: 30 ноя 2024

Комментарии • 7

  • @krishnabadrib1706
    @krishnabadrib1706 Год назад +1

    Do Soc analyst L1 will do this in office!

    • @SudoRootcast
      @SudoRootcast  Год назад +1

      Not sure, Its Depends Usually L2 and L3. Thanks!

  • @Fmd63067
    @Fmd63067 4 месяца назад

    what is authpriv? failed login attempts in authpriv, Is it like a table of logs?

    • @SudoRootcast
      @SudoRootcast  4 месяца назад

      unix.stackexchange.com/questions/59525/difference-between-authpriv-and-auth

  • @RaniUG
    @RaniUG Год назад

    Are data connector , , analytic rule playbook are interconnected?

  • @VivekSharma-vy1xk
    @VivekSharma-vy1xk Год назад +1

    Great content. I followed it step wise for MFA related Incidents. It failed me on 3rd step with error : 
    ExpressionEvaluationFailed. The execution of template action 'For_each' failed: the result of the evaluation of 'foreach' expression '@triggerBody()?['object']?['properties']?['Alerts']' is of type 'Null'. The result must be a valid array. Am I missing something here?