Azure / Azure-Sentinel

Cloud-native SIEM for intelligent security analytics for your entire enterprise.
https://azure.microsoft.com/en-us/services/azure-sentinel/
MIT License
4.46k stars 2.94k forks source link

Data between Sentinel and Logic App not the same #2340

Closed Lodewyk-Git closed 3 years ago

Lodewyk-Git commented 3 years ago

I was playing around with a Playbook, so I set up an Analytical rule to trigger it every five minutes, before testing it using the automation rule I changed the description of the analytical rule, but in my email the description was unchanged, thus leaving me to believe that the Get Incident flow, or something, is not working correctly.

The automation rule that takes all high severity Incidents and runs the playbook The email gets the AlertName and Description from the GetIncident flow

Screenshots

Email image Sentinel image Logic App image

github-actions[bot] commented 3 years ago

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

Lodewyk-Git commented 3 years ago

Is this the right place to post this or should I open an issue at https://github.com/Azure/logicapps/issues?

sreedharande commented 3 years ago

@Lodewyk-Git - This is the correct forum

github-actions[bot] commented 3 years ago

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.