FortiSOAR Discussions
gwaihir
New Contributor III

Why can't I run created playbooks on Alerts/Incidents?

Hello Community.

 

I'm trying to run some newly created playbooks with Manual Trigger using csadmin user, then I want to run it on ingested alerts from SIEM or escalated alerts (incidents) using the Execute option at the bottom of each record, but I can't see the playbooks that I want to run. Why is this happening?

 

Regards!

1 Solution
ranjeet
New Contributor III

Hi @gwaihir ,

 

  • First, ensure that the playbook is in an active state.

PB Active State.PNG

 

 

  • Make sure that the Trigger Button Label is not empty. If you want to run the playbook on an alert, select the alert in the "Execution Behaviour" settings.

Trigger Button.PNG

 

  • After setting the trigger point, go to alerts and refresh the FortiSOAR webpage. Then, select an alert and click on "Execute".  You should see the Trigger Button Label you set in the trigger point, along with the playbook collection name where the playbook is located.

 

Execute From Alert.PNG

 

 

If you need assistance or more details, feel free to reach out to me at ranjeet.nagane@spryiq.co or swapnil@spryiq.co.

 

View solution in original post

2 REPLIES 2
ranjeet
New Contributor III

Hi @gwaihir ,

 

  • First, ensure that the playbook is in an active state.

PB Active State.PNG

 

 

  • Make sure that the Trigger Button Label is not empty. If you want to run the playbook on an alert, select the alert in the "Execution Behaviour" settings.

Trigger Button.PNG

 

  • After setting the trigger point, go to alerts and refresh the FortiSOAR webpage. Then, select an alert and click on "Execute".  You should see the Trigger Button Label you set in the trigger point, along with the playbook collection name where the playbook is located.

 

Execute From Alert.PNG

 

 

If you need assistance or more details, feel free to reach out to me at ranjeet.nagane@spryiq.co or swapnil@spryiq.co.

 

gwaihir
New Contributor III

Hello @ranjeet thank you for your reply, works perfectly!