SNOW -Teams

This is snow and teams integration

Rsource Visualiser

Logic App Flows

Components Settings

  1. MS Sentinel

  2. adaptiveCardItems

  3. Extract entities and add to adaptive card -4 actions

  4. SNOW- Query for sentinel Incident Number

  5. Check to see if SNOW Incident Exists - 2 cases

    Function

  6. Compose Teams Incident Alert Card

  1. Post Incident in SOC Alerts Channel

  2. Post Actions Required in Investigation Request channel

  1. Update incident thread from investigation Response

  2. SNOW update Record with response from user

  3. Grab Selected playbooks from investigation response

  1. Loop though each playbook and run it -5 actions

Loop through :-

  1. find playbook based on playbook name provided

URI

  1. Teams Reply Text

  2. SNOW add additional comments in SNOW ticket

  1. MS Sentinel Add comment to releated Incident

Section : 5 Check If SNOW Incident Exist

True:

value:

False :

Section 3: Extract Entities and add to adaptive card

From

SNOW Team -IPCheckon VT

from

Last updated