question

GrexaJuraj-8393 avatar image
1 Vote"
GrexaJuraj-8393 asked dhruvjain commented

Azure Sentinel trigger in Logic App (Standard)

Hello,

I have tried to create Logic App (Standard) with Sentinel with trigger "When Azure Sentinel incident creation rule was triggered", but Logic App is not receiving any calls from Sentinel.
Automation rule "When incident is created" is set up on Sentinel to send all incidents to Logic App.
Enterprise app "Azure Security Insights" has role "Azure Sentinel Automation Contributor" in the Resource Group with Logic App.

Does it mean Logic App Standard is not supported as Playbook for Sentinel now? Or maybe there is some other issue with my setup? Everything works ok with Logic App Consumption. I wanted to use Standard version due to VNET support.

azure-logic-appsmicrosoft-sentinel
· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hello @GrexaJuraj-8393, Welcome to Microsoft QnA. Thank you for the question. I have tried to replicate at my end. Currently I am discussing this with the product team. I will share the updates at the earliest.

0 Votes 0 ·
dhruvjain avatar image
0 Votes"
dhruvjain answered dhruvjain commented

I am facing the same issue. Did you get any update?

· 2
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hi,
this is still not working. I contacted MS support, but they were not able to answer if its supported scenario or not.
I have implemented following workaround successfully:
Sentinel -> Logic App (consumer) with Incident trigger -> Logic App (Standard) with http trigger -> VNET
IThis solution has one more step, but is working correctly.

0 Votes 0 ·

I also contacted MS Support today and they have informed me:

"It appears that logic app standard is not yet integrated with sentinel so, I will check with our product group to get possible ETA on the same supportability."

This is such a lack of integration because I wanted to secure everything in a VNet.

1 Vote 1 ·
JayaC-MSFT avatar image
0 Votes"
JayaC-MSFT answered

Hello @GrexaJuraj-8393, After initial investigation, looks like it needs dedicated troubleshooting. Hence I would request you to open a support ticket with Microsoft Support if you have a subscription which allows you to do so. Otherwise , you can send an email with subject line “Attn:Jaya” to AzCommunity[at]Microsoft[dot]com referencing this thread along with the subscription id.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.