I have created a draft workflow to test it’s trigger condition which is on InsightIDR –> Get New Investigations, and I have set the condition in this way: [{"field":"title","operator":"EQUALS","value":"Microsoft Defender for Cloud Apps - C2C - Adminsitrative Activity from a non-corporate IP address"}]. We have investigations created with that title in huge number. But, the workflow didn’t trigger for any of them.
As per Information I have, When the workflow’s trigger point is created with InsightIDR version 12.0.0, the workflow will work. When plugin’s version is higher than workflow won’t trigger. Looks like the problem is with plugin itself.
This user is right, using an older version of the template with an older plugin works perfectly. I’ll have to do some more digging. The monitor for changes workflow still doesn’t trigger but I think I’m close to the end of this mystery
I have setup two workflows in our internal environment to test the comments above about 12.0.0 being the last version that worked, because I haven’t actually heard of this issue.
They both fire just fine. 12.0.0 and the latest version.
I am using a platform API key, not a user API key.