Hello Fortinet Community,
I'm currently working with FortiAnalyzer (version 7.4.x) and have set up an automation playbook that triggers upon specific events, such as multiple failed login attempts. The playbook includes a webhook action intended to send event details, including the ADOM (Administrative Domain) information, to an external system.
In my webhook action, I'm attempting to include the ADOM using the ${adom} macro in my automation Playbook.
However, the adom field in the payload is coming through as blank. I understand that in notification profiles, the ADOM information is readily available, but it seems that in the context of playbook actions, this macro isn't being populated.
I've reviewed the FortiAnalyzer documentation, particularly the section on webhook connectors and supported macros , but it doesn't provide clarity on this specific issue.
Has anyone encountered this problem or found a workaround to include the ADOM information in playbook webhook actions? Any guidance or suggestions would be greatly appreciated.
Thank you!
FortiAnalyzer
Hello fortinet_sdwan,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello,
We are still looking for an answer to your question.
We will come back to you ASAP.
Thanks,
Hello again fortinet_sdwan,
I found this solution, can you tell me if it helped?
In FortiAnalyzer, the use of macros like `${adom}` in playbooks can sometimes lead to issues if the context in which they are used does not support them. Here are some steps to troubleshoot and resolve the issue:
User | Count |
---|---|
2612 | |
1390 | |
804 | |
666 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.