Sentinel has two automation layers. Automation rules are lightweight, built-in rules that run when incidents are created or updated, or when alerts are created. They can change status, severity or owner, add tags, add incident tasks and run playbooks. Rules have an order number (lower runs first), an optional expiration date, and conditions such as analytics rule name, severity, tag or entity values. They are ideal for triage: assign all phishing incidents to the email team, raise severity when a VIP account is involved, or close known-benign incidents automatically, perhaps for a limited time while a rule is fixed.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.