diff --git a/Solutions/MicrosoftPurviewInsiderRiskManagement/Package/3.0.1.zip b/Solutions/MicrosoftPurviewInsiderRiskManagement/Package/3.0.1.zip index 81c701d33d7..5e4b7f0200a 100644 Binary files a/Solutions/MicrosoftPurviewInsiderRiskManagement/Package/3.0.1.zip and b/Solutions/MicrosoftPurviewInsiderRiskManagement/Package/3.0.1.zip differ diff --git a/Solutions/MicrosoftPurviewInsiderRiskManagement/Package/mainTemplate.json b/Solutions/MicrosoftPurviewInsiderRiskManagement/Package/mainTemplate.json index 3b041f930d4..b0bfbcd8202 100644 --- a/Solutions/MicrosoftPurviewInsiderRiskManagement/Package/mainTemplate.json +++ b/Solutions/MicrosoftPurviewInsiderRiskManagement/Package/mainTemplate.json @@ -975,7 +975,7 @@ "type": "ApiConnection", "inputs": { "body": { - "messageBody": "

Insider Risk Team,
\n
\nAn Insider Risk Management Alert was observed per the details below:
\n
\nSeverity of Alert: @{items('For_each')?['properties']?['severity']}
\n
\nAzure Sentinel Incident
\nTItle: @{triggerBody()?['object']?['properties']?['title']}
\nStatus: @{triggerBody()?['object']?['properties']?['status']}
\nNumber: @{triggerBody()?['object']?['properties']?['incidentNumber']}
\nCreated Time (UTC): @{triggerBody()?['object']?['properties']?['createdTimeUtc']}
\nIncident Link:  @{triggerBody()?['object']?['properties']?['incidentUrl']}
\n
\nAlert Details
\nAlert Display Name: @{items('For_each')?['properties']?['alertDisplayName']}
\nAlert Type: @{items('For_each')?['properties']?['alertType']}
\nSubscription ID: @{triggerBody()?['workspaceInfo']?['SubscriptionId']}
\nProvider Alert ID: @{items('For_each')?['properties']?['providerAlertId']}
\nAlert Link: @{items('For_each')?['properties']?['alertLink']}

", + "messageBody": "

Insider Risk Team,
\n
\nAn Insider Risk Management Alert was observed per the details below:
\n
\nSeverity of Alert: @{items('For_each')?['properties']?['severity']}
\n
\nMicrosoft Sentinel Incident
\nTItle: @{triggerBody()?['object']?['properties']?['title']}
\nStatus: @{triggerBody()?['object']?['properties']?['status']}
\nNumber: @{triggerBody()?['object']?['properties']?['incidentNumber']}
\nCreated Time (UTC): @{triggerBody()?['object']?['properties']?['createdTimeUtc']}
\nIncident Link:  @{triggerBody()?['object']?['properties']?['incidentUrl']}
\n
\nAlert Details
\nAlert Display Name: @{items('For_each')?['properties']?['alertDisplayName']}
\nAlert Type: @{items('For_each')?['properties']?['alertType']}
\nSubscription ID: @{triggerBody()?['workspaceInfo']?['SubscriptionId']}
\nProvider Alert ID: @{items('For_each')?['properties']?['providerAlertId']}
\nAlert Link: @{items('For_each')?['properties']?['alertLink']}

", "recipient": { "channelId": "[[parameters('TeamschannelId')]", "groupId": "[[parameters('TeamsgroupId')]" @@ -999,7 +999,7 @@ "type": "ApiConnection", "inputs": { "body": { - "Body": "

Insider Risk Team,
\n
\nAn Insider Risk Management Alert was observed per the details below:
\n
\n
\nAzure Sentinel Incident
\nTItle: @{triggerBody()?['object']?['properties']?['title']}
\nStatus: @{triggerBody()?['object']?['properties']?['status']}
\nNumber: @{triggerBody()?['object']?['properties']?['incidentNumber']}
\nIncident Severity: @{triggerBody()?['object']?['properties']?['severity']}
\nCreated Time (UTC): @{triggerBody()?['object']?['properties']?['createdTimeUtc']}
\nIncident Link:  @{triggerBody()?['object']?['properties']?['incidentUrl']}
\n
\nAlert Details
\nAlert Display Name: @{items('For_each')?['properties']?['alertDisplayName']}
\nAlert Product Name: @{items('For_each')?['properties']?['productName']}
\nAlert Severity: @{items('For_each')?['properties']?['severity']}
\nAlert Type: @{items('For_each')?['properties']?['alertType']}
\nSubscription ID: @{triggerBody()?['workspaceInfo']?['SubscriptionId']}
\nProvider Alert ID: @{items('For_each')?['properties']?['providerAlertId']}
\nAlert Link: @{items('For_each')?['properties']?['alertLink']}

", + "Body": "

Insider Risk Team,
\n
\nAn Insider Risk Management Alert was observed per the details below:
\n
\n
\nMicrosoft Sentinel Incident
\nTItle: @{triggerBody()?['object']?['properties']?['title']}
\nStatus: @{triggerBody()?['object']?['properties']?['status']}
\nNumber: @{triggerBody()?['object']?['properties']?['incidentNumber']}
\nIncident Severity: @{triggerBody()?['object']?['properties']?['severity']}
\nCreated Time (UTC): @{triggerBody()?['object']?['properties']?['createdTimeUtc']}
\nIncident Link:  @{triggerBody()?['object']?['properties']?['incidentUrl']}
\n
\nAlert Details
\nAlert Display Name: @{items('For_each')?['properties']?['alertDisplayName']}
\nAlert Product Name: @{items('For_each')?['properties']?['productName']}
\nAlert Severity: @{items('For_each')?['properties']?['severity']}
\nAlert Type: @{items('For_each')?['properties']?['alertType']}
\nSubscription ID: @{triggerBody()?['workspaceInfo']?['SubscriptionId']}
\nProvider Alert ID: @{items('For_each')?['properties']?['providerAlertId']}
\nAlert Link: @{items('For_each')?['properties']?['alertLink']}

", "Subject": "Insider Risk Management Alert", "To": "[[parameters('Email')]" },