Automation Playbooks
A sequence of one or more actions offered by SOC connectors can be defined in playbooks and executed manually or automatically.
Playbooks consist of a trigger and multiple actions from configured connectors.
- Playbook triggers include:
- Incident
- Event
- On Schedule
- On Demand
- Playbook actions:
- This is the automated action taken by the playbook at any step.
- Actions can be configured with default input values or take inputs from the trigger or preceding actions.
- Actions be selected from the local FortiAnalyzer or a configured connector's list of actions.
Connectors
To view FortiSoC connectors:
- View the connector list from FortiSoC > Automation > Connectors.
- Click on a connector to view its details.
The actions available with each connector are displayed, including the action name, and the action's parameters used in the playbook.- EMS connectors:
- FOS connectors:
- Local connectors:
- EMS connectors:
Playbooks
To create a playbook:
- Click Create New from the Playbook list, and select a template.
You can also select New Playbook created from scratch to start with a blank playbook. - Provide a name and description for the playbook, and set it to Enabled if you want to use it immediately after saving the playbook.
- If a predefined template is selected, check each trigger and task configuration, and update them as need by clicking the edit icon.
- If a playbook is created from scratch, select trigger and trigger filter conditions.
- Add a task by clicking the connector point of a parent task or trigger and dragging-and-dropping a new task onto the playbook.
- Select the Connector type.
- Enter a name, description, and the ID for the task.
- Select a connector and action, and enter the action's required parameters. The parameter may come from any parent task/trigger output or be a fixed value.
- Click OK to save your changes.
- Save the playbook once finished and the playbook will appear in the playbook list.
To run an on-demand playbook:
- Go to FortiSoC > Automation > Playbooks.
- Select a playbook configured with an On_Demand trigger.
- Click Run in the toolbar or through the context menu of the selected playbook.
- Input the desired parameters if prompted.
Playbooks with an Incident, Event, or On_Schedule trigger run automatically once the trigger's filter is matched.
Playbook Monitor
To view the Playbook Monitor:
- Go to FortiSoC > Automation > Playbook Monitor.
All playbook jobs that are running or have been run are displayed. - Double-click a job or click the details icon in the status column to view the playbook status details.