SNOW -Teams
This is snow and teams integration
Rsource Visualiser

Logic App Flows


Components Settings
MS Sentinel

adaptiveCardItems

Extract entities and add to adaptive card -4 actions

SNOW- Query for sentinel Incident Number

Check to see if SNOW Incident Exists - 2 cases

Function
Compose Teams Incident Alert Card

Post Incident in SOC Alerts Channel

Post Actions Required in Investigation Request channel

Update incident thread from investigation Response

SNOW update Record with response from user

Grab Selected playbooks from investigation response

Loop though each playbook and run it -5 actions


Loop through :-
find playbook based on playbook name provided

URI
Teams Reply Text

SNOW add additional comments in SNOW ticket

MS Sentinel Add comment to releated Incident

Section : 5 Check If SNOW Incident Exist

True:

value:
False :



Section 3: Extract Entities and add to adaptive card




From





SNOW Team -IPCheckon VT



from



Last updated
