Skip to content

Conversation

ZaidAlKhayyat-MSFT
Copy link

@ZaidAlKhayyat-MSFT ZaidAlKhayyat-MSFT commented Sep 28, 2025

This workbook extracts Incidents and alerts based on the department tag attached to VMs hosted on Azure. It extracts hosts from alerts and tag from ARG then correlates it with the incidents. Azure VMs tags are uploaded using Watchlist on Sentinel.

Required items, please complete

Change(s):

  • New idea deployment

Reason for Change(s):

  • New idea deployment

Testing Completed:

  • Yes

Checked that the validations are passing and have addressed any issues that are present:

  • I have tested the KQL queries.

This workbook extracts Incidents and alerts based on the department tag attached to VMs hosted on Azure. It extracts hosts from alerts and tag from ARG then correlates it with the incidents. Azure VMs tags are uploaded using Watchlist on Sentinel.
@ZaidAlKhayyat-MSFT ZaidAlKhayyat-MSFT requested review from a team as code owners September 28, 2025 09:23
@ZaidAlKhayyat-MSFT
Copy link
Author

@microsoft-github-policy-service agree

@v-atulyadav v-atulyadav self-assigned this Sep 29, 2025
@v-atulyadav v-atulyadav added the Workbook Workbook specialty review needed label Sep 29, 2025
@v-atulyadav
Copy link
Contributor

Hi @ZaidAlKhayyat-MSFT,

Could you please update the metadata for the workbook located at the path mentioned below? Let me know if you need help with the specific values or format. Thanks

https://github.com/Azure/Azure-Sentinel/blob/master/Workbooks/WorkbooksMetadata.json

@v-atulyadav
Copy link
Contributor

Hi @ZaidAlKhayyat-MSFT,
Any update on the request mentioned above? Thanks

@v-atulyadav
Copy link
Contributor

Hi @ZaidAlKhayyat-MSFT,
We are still awaiting your response. Thanks

@v-atulyadav
Copy link
Contributor

Hi @ZaidAlKhayyat-MSFT,
We are still awaiting your response. Kindly provide an update at your earliest convenience. Thanks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Workbook Workbook specialty review needed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants