An Azure Logic App sends the Sentinel incident to n8n.
Microsoft Sentinel + n8n
Microsoft Sentinel Incident Triage
An end-to-end incident triage system designed for Microsoft Sentinel. It combines webhook ingestion, normalized incident records, entity tables, decision tracking, false-positive learning, daily metrics, and an Azure Logic App integration path.
8Data tables
3Live workflows
100Test risk score
SYSTEM ARCHITECTURE
From raw signal to accountable decision.
Incident and entity fields are normalized into dedicated tables.
Risk logic builds an explainable L1 recommendation.
Decisions and daily metrics make triage quality measurable.
PROCESS
01Webhook02Normalize03Entities04Risk05Decision06Metrics
CAPABILITIES
What the automation delivers.
Sentinel incident webhook
Eight structured data tables
Entity correlation
Decision API
False-positive tracker
Logic App connection guide
SAMPLE OUTPUT
Multi-stage identity compromise
SEVERITYCritical
RISK SCORE100 / 100
RECOMMENDATIONImmediate escalation
Webhook endpoint: /webhook/sentinel-incident