Raise an incident when an outbreak is detected
Newly downloaded Outbreak Alert event handlers in FortiAnalyzer 7.6.0 and later will automatically create incidents when an outbreak is detected. This is done using the new Automatically Create Incident option. For more information about this option, see Automatically raise actionable events for incident investigation.
Outbreak Alert event handlers that exist prior to upgrading to 7.6.0 or later will not have Automatically Create Incident enabled. For example, see below where Automatically Create Incident = No.
However, newly downloaded Outbreak Alert event handlers have Automatically Create Incident enabled. For example, see below where Automatically Create Incident = Yes. All of these handlers were loaded after creating a new ADOM in 7.6.0.
The Automatically Create Incident option can be updated according to your needs by editing an Outbreak Alert event handler.
Incidents automatcally created by Outbreak Alert event handlers can be found in Incidents & Events > Incidents > Incidents.