This automation (Logics Apps) provides to close SAMPLE ALERTS from Microsoft Defender for Cloud. Playbook will act the following sequences:
- Detect [SAMPLE ALERTS] naming from Incident Title
- Change to Severity as Informational.
- Incident Close and reason as "Undetermined" and comments as "サンプルアラートのためクローズ"
- Add Tag as "SAMPLE".
Here is a instruction to install Automation template for Sentinel.
This button will provide deploys playbook.
This template create Logic Apps that is used authentication by Managed ID.
The workflow requires 'Microsoft.SecurityInsights/incidents/read' to the target Microsoft Sentinel, so please assign suitable role for managed id.
Here is a sample