---
title: "Creating Automation Rule"
canonical: "https://docs.infoblox.com/space/DeploymentGuideInfobloxAppforSentinel/1543307281/Creating%20Automation%20Rule"
format: markdown
---
You can configure Automation Rule to bring in enriched data for a SOC Insights. Here are the steps for that.

1. Go to Microsoft Sentinel → < your workspace > → Automation → Create → Automation rule

![image-20250710-082417.png](media://1eeb0fbc-9899-4fba-b2f3-ca9f52f3e73c)

2. Set Automation rule name

![image-20250710-082446.png](media://7b8176e7-24cb-4f33-90ac-54efefa9bcd3)

3. Condition → If:
  1. Incident provider → Select Microsoft Sentinel
  2. Analytic rule name → Select Analytic rule name created

![image-20250710-082514.png](media://35a02f01-f0bb-490a-8b46-619ceb359671)


4. Action → Select Run playbook

![image-20250710-082536.png](media://5e9d62a1-6dcb-4416-8d4d-32dbdee5bea8)

5. Select Infoblox-SOC-Get-Insight-Details playbook

![image-20250710-082547.png](media://e7c7a774-16a4-44c8-8aae-0783e43da873)

6. Click on Apply

![image-20250710-082600.png](media://f325bde8-783a-45e1-af68-5b0b0a904e84)