Skip to main content

Synchronize Torq Case State Change to Microsoft Sentinel Incident - Workflow Template

Synchronize Torq Case Change of State to a Sentinel Incident driven by a "State changed" Trigger.

Updated yesterday

This workflow template automates the synchronization of Torq case state changes to corresponding Microsoft Sentinel incidents, ensuring timely and accurate communication with external stakeholders. By mapping Torq case states to Sentinel incident statuses, the workflow maintains consistency between systems, enhancing incident response efficiency. Utilize this seamless integration for streamlined case management and improved collaboration across platforms.

Use Cases

Case Management

Workflow Breakdown

  1. Workflow triggers when a case state changes.

  2. Fetch Sentinel Incident ID from Case Custom Fields.

  3. Map Torq Case States with Microsoft Sentinel Incident States.

  4. Creates a new session on Microsoft Sentinel and updates an incident with the updated state.

Vendors

Utils, Torq Cases, Microsoft Sentinel

Tips

Did this answer your question?