You need to ensure that the processing of incidents generated by rulequery1 meets the Microsoft Sentinel requirements.
What should you create first?
a playbook with an incident trigger
a playbook with an entity trigger
an Azure Automation rule
a playbook with an alert trigger
Submit