Skip to main content

Synchronize Torq Case Severity to Microsoft Sentinel Incidents - Workflow Template

Synchronize Torq Case Severity to a Sentinel Incident driven by a "Severity changed" Trigger.

Updated yesterday

The "Synchronize Torq Case Severity to Microsoft Sentinel Incidents" workflow streamlines incident management by automatically updating Microsoft Sentinel incidents when there is a change in the severity of a Torq case. This ensures that all relevant information is consistently communicated, allowing businesses to maintain synchronization between their internal processes and Sentinel, improving response efficiency and stakeholder communication.

Use Cases

Case Management

Workflow Breakdown

  1. Workflow triggers when severity is changed.

  2. Fetch Sentinel Incident ID from Case Custom Fields.

  3. Creates a new session on Microsoft Sentinel and updates an incident with the accurate Severity.

Vendors

Utils, Torq Cases, Microsoft Sentinel

Tips

Did this answer your question?