This workflow template automates the synchronization of Torq case state changes to corresponding Microsoft Sentinel incidents, ensuring timely and accurate communication with external stakeholders. By mapping Torq case states to Sentinel incident statuses, the workflow maintains consistency between systems, enhancing incident response efficiency. Utilize this seamless integration for streamlined case management and improved collaboration across platforms.
Use Cases
Case Management
Workflow Breakdown
Workflow triggers when a case state changes.
Fetch Sentinel Incident ID from Case Custom Fields.
Map Torq Case States with Microsoft Sentinel Incident States.
Creates a new session on Microsoft Sentinel and updates an incident with the updated state.
Vendors
Utils, Torq Cases, Microsoft Sentinel
Tips