Workarounds for Azure Sentinel SIR Closure

designitsecure
Tera Expert

Hello,

 

Has anyone implemented a workaround to have Sentinel close SIR incidents since the integration is not bi-directional in this regard?

 

Thanks!

9 REPLIES 9

Pooja P
Tera Contributor

Can you please confirm if we use this checkbox it will automatically update the status of sentinel and update SIR to closed from draft state?

charankollapudi
ServiceNow Employee
ServiceNow Employee

Its available in the 11.0.24 store version.
You can Enable the 'Pull Closed Incidents' option to fetch the closed incidents during the ingestion.

Hi @charankollapudi ,

Can you please confirm if we use this checkbox it will automatically update the status of sentinel and update SIR to closed from draft state?

When polling closed incidents, the state of SIR corresponding to it will be in closed state.

Hi @charankollapudi this is excellent news.

Do you know if an update will be written for the Documentation, as there doesn't yet appear to be an explanation of how to use the latest updates from what I can see.

Thanks, AJ