Microsoft Sentinel rule triggered when an incident or alert from any source is created or updated, used to centrally set status, assign owners, apply tags and launch playbooks.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Automation rule in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Sentinel
Microsoft's cloud-native SIEM, with SOAR capabilities, which stores and queries its data in a Log Analytics workspace.
- Incident
A case that Microsoft Defender XDR or Microsoft Sentinel builds by correlating several alerts that look like parts of one attack. It lists the assets involved and the evidence, and analysts can assign it and update its status as they investigate.
- Set
Secret permission in Key Vault for writing secrets; some older material refers to it as Create.
- APPLY
Evaluates a table-valued expression for every row on its left, inside
FROM. Think ofOUTER APPLYas a left outer join andCROSS APPLYas an inner join. - Image tagging
An Image Analysis feature producing single-word tags, each with a confidence score, for actions, scenery, objects and living things in an image.
Related terms
- Playbook
Response automation for Microsoft Sentinel built as a Logic Apps workflow, triggered manually or by an automation rule to do things like block IPs, open tickets or assign incidents. Launching one directly from an analytics rule is retired.