You have a Microsoft Sentinel workspace. You need to create a playbook that will run automatically in response to a Microsoft Sentinel incident. What should you create first? a hunting query a logic app a trigger an automation rule

Based on the provided contexts, the correct answer to your question is: you should create a logic app first. This is because Microsoft Sentinel playbooks, which run preconfigured sets of remediation actions in response to alerts or incidents, make use of Azure Logic Apps. Therefore, creating a logic app is the first step in creating a playbook that will run automatically in response to a Microsoft Sentinel incident.

[2] [3] [5] [8]

References

Any other questions?