You must modify existing Logic App and choose Azure Sentinel actions either the following ones: - When a response to an Azure Sentinel Alert is triggered - When Azure Sentinel incident creation rule was triggered https://docs.microsoft.com/en-us/azure/sentinel/tutorial-respond-threats-playbook