Skip to main content

Synchronize Torq Case Assignee to Microsoft Sentinel Incidents - Workflow Template

Synchronize Torq Case Assignee to a Sentinel Incident driven by a "Assigned to teammate" Trigger.

Updated yesterday

The "Synchronize Torq Case Assignee to Microsoft Sentinel Incidents" workflow template facilitates seamless integration between Torq and Microsoft Sentinel, enabling efficient case management. By automatically synchronizing case assignee changes to associated Sentinel incidents, teams can ensure prompt and coordinated incident response. This integration improves communication and collaboration with external stakeholders through Sentinel, enhancing overall operational efficiency.

Use Cases

Case Management

Workflow Breakdown

  1. Workflow triggers when case is assigned to a new teammate.

  2. Fetch Sentinel Incident ID from Case Custom Fields.

  3. Creates a new session on Microsoft Sentinel and updates an incident with the new Assignee.

Vendors

Utils, Torq Cases, Microsoft Sentinel

Tips

Did this answer your question?