Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Jack_wack
New Contributor III

Which executed playbook's template should I use in foritanalyzer (FAZ) ?

I'd like to set up an executed playbook within an unhandled (not mitigated by FGT) incident.

It's job is to send back the malicious event to fortigate (FGT) and have it mitigated automatically.

Which playbook's template does fit this need ? and which associated "Action" ?

 

It's about a malware hasn't been blocked by FGT and it shows "passthrough" in FAZ.

 

 

1 Solution
dbu
Staff
Staff

I believe you need to create a new Playbook with trigger " INCIDENT_TRIGGER ", connector "FortiOS" and the actions depends on the automation rules configured on each FortiGate. 

 

https://docs.fortinet.com/document/fortigate/7.4.1/administration-guide/51460/actions
https://docs.fortinet.com/document/fortianalyzer/7.4.1/administration-guide/28682/playbooks

 

Regards!
If you have found a solution, please like and accept it to make it easily accessible for others.

View solution in original post

3 REPLIES 3
dbu
Staff
Staff

I believe you need to create a new Playbook with trigger " INCIDENT_TRIGGER ", connector "FortiOS" and the actions depends on the automation rules configured on each FortiGate. 

 

https://docs.fortinet.com/document/fortigate/7.4.1/administration-guide/51460/actions
https://docs.fortinet.com/document/fortianalyzer/7.4.1/administration-guide/28682/playbooks

 

Regards!
If you have found a solution, please like and accept it to make it easily accessible for others.
Jack_wack
New Contributor III

thanks for the quick and helpful response.

I thought there might be a template for it. But I've understood I should create one from scratch.

 

The trigger and the connector are clear to me.

yet I have to dive in the Actions because I want the fortigate to mitigate it or put it in quarantine automatically., not just send a notification.

 

 

thanks again

Labels
Top Kudoed Authors