Creating incident sequence rules
You can create a maximum of 10 incident sequence rules.
To create a rule, follow the steps below.
How to create an incident sequence rule
- In the FortiDLP Console, on the left-hand sidebar, click
.
- Select the Sequence rules tab.
- Click Create new rule.
- In the New incident rule dialog box, do the following:
- In the Name field, type a rule name.
- Optionally, in the Description field, type a rule description.
- Click Next.
- Select the checkboxes for at least two stages to incorporate into the rule.
- Click Create.
- Click Edit.

- Set the sequence rule's scope by doing one of the following. Note that the rule will only be applied to the entities you select if the entities have also been assigned policies for the rule's stages:
- To apply the rule to all entities:
- In the Include section, leave the All entities radio button selected.
- In the Exclude section, leave the No entities radio button selected.
- Click Save.
- To apply the rule to a subset of entities by only selecting labels to include:
- In the Include section, select the Specific entities radio button.
- In the label list, select one or more labels for the entities you want to apply the rule to.
- Do one of the following:
- To include entities that have all of the previously selected labels, select the Require all radio button.
- To include entities that have any of the previously selected labels, select the Require any radio button.
- Click Save.

For example, to apply a rule to all entities with a "Sales" label or a "Finance" label:
In the Include section:
- Select the Specific entities radio button.
- In the labels list, select the Sales and Finance labels.
- Select the Require any radio button.
- To apply the rule to a subset of entities by selecting labels to include and exclude:
- In the Include section, follow the steps detailed above.
- In the Exclude section:
- Select the Specific entities radio button.
- In the label list, select one or more labels for the entities you want to exclude from the rule.
- Do one of the following:
- To exclude entities that have all of the previously selected labels, select the Require all radio button.
- To exclude entities that have any of the previously selected labels, select the Require any radio button.
- Click Save.

For example, to apply a rule to all entities except those with a "Sales" label or a "Finance" label:
- In the Include section, select the All entities radio button.
- In the Exclude section:
- Select the Specific entities radio button.
- In the labels list, select the Sales and Finance labels.
- Select the Require any radio button.
Or, to apply a rule to entities with a "Manager" label and a "Product" label, but not a "Windows" label:
- In the Include section:
- Select the Specific entities radio button.
- In the labels list, select the Manager and Product labels.
- Select the Require all radio button.
- In the Exclude section:
- Select the Specific entities radio button.
- In the labels list, select the Windows label.
- Select either the Require all or Require any radio button.
- To apply the rule to all entities:
- Set the sequence rule's match type and mandatory stages:
- In the Match type widget, click
.
- Do one of the following:
- To generate an incident after a policy detection occurs in all of the selected stages, select the Match all stages radio button.
- To generate an incident after a policy detection occurs in a subset of the selected stages, select the Match ≥ N stages (including mandatory) radio button and then optionally select the checkboxes for any stages you want to be mandatory.

For example, if a rule contains four stages and you select Match ≥ 2 stages, an incident will be generated after a policy detection occurs in any two of the four stages during the given time window.
Alternatively, if you select Match ≥ 2 stages and make two of the stages mandatory, an incident will be generated after a policy detection occurs in both of the specified stages during the given time window.
- Click Save.
- In the Match type widget, click
- Set the sequence rule's risk score:
- In the Risk score widget, select
.
- Do one of the following:
- To use a fixed risk score for the incident, which is applied regardless of the detections it comprises, leave the Fixed radio button selected and type a number between 1–100:
- A risk score of 0 is classified as no severity.
- A risk score between 1–39 is classified as low severity.
- A risk score between 40–69 is classified as medium severity.
- A risk score between 70–89 is classified as high severity.
- A risk score between 90–100 is classified as critical severity.
- To use the risk score of the most severe detection the incident comprises, select the Most severe detection radio button.
- To use a fixed risk score for the incident, which is applied regardless of the detections it comprises, leave the Fixed radio button selected and type a number between 1–100:
- Exit the menu.
- In the Risk score widget, select
- Set the sequence rule's time window:
- In the Time window widget, click
.
- Select the time window during which policy detections for selected stages must occur for an incident to be generated.
- Exit the menu.
- In the Time window widget, click
- Set the sequence rule's operation mode:
- In the Operation mode widget, click
.
- Do one of the following:
- To disable the rule after configuration, leave the Disabled radio button selected.
- To enable the rule after configuration, select the Enabled radio button.
- To test the rule after configuration, select the Test radio button.

A rule is effective when it is enabled and published, as described later in these instructions.

Incidents generated in the "Test" operation mode will be shown in the Incidents module like other incidents, but can be filtered for rule testing purposes.
- Exit the menu.
- In the Operation mode widget, click
- Customize each of the sequence rule's stages:
- Optionally, to define a minimum risk score a policy must have to be included in a stage, type a number between 1–100, referring to the severity scale above. Leave this set to 0 to include all policies in the stage.

- To disable a policy in a stage, turn its Enabled toggle off.
- To configure policy template parameters, click
. For detailed instructions on this, see Configuring policy templates.
- Optionally, to define a minimum risk score a policy must have to be included in a stage, type a number between 1–100, referring to the severity scale above. Leave this set to 0 to include all policies in the stage.
- Do one of the following:
- To publish the rule now, click Publish rule and then click Publish in the dialog box that displays.
- To publish the rule later, exit the sequence rule page and see Publishing incident sequence rules for instructions when you are ready.