Fortinet white logo
Fortinet white logo

FortiDLP Administration Guide

Publishing incident sequence rules

Publishing incident sequence rules

After you configure a sequence rule, you must publish it to make it effective for applicable entities.

You can publish a sequence rule immediately. Alternatively, if you need more time to review your rule before pushing it to entities, you can save a draft and publish the rule later.

The instructions for publishing a sequence rule immediately are described in Creating incident sequence rules. To publish a draft sequence rule, follow these steps.

How to publish an incident sequence rule draft
  1. In the FortiDLP Console, on the left-hand sidebar, click .
  2. Select the Sequence rules tab.
  3. Do one of the following:
    • To review/update the configuration prior to publishing the rule:
      1. Click the rule you want to publish.
      2. Edit the rule as needed, referring to Editing incident sequence rules and Creating incident sequence rules for instructions.
      3. Verify the Enabled toggle is turned on for all the policies you want to include in the rule stages.
      4. Verify the Operation mode toggle is set to Enabled for the rule.
      5. Note

        A rule is effective when it is enabled and published.

      6. Click Publish rule.
      7. In the Publish incident rule dialog box, click Publish.
    • To publish the rule without reviewing/updating the configuration:
      1. On the right-hand side of the row for the relevant rule, click Publish.
      2. In the Publish incident rule dialog box, click Publish.

Publishing incident sequence rules

Publishing incident sequence rules

After you configure a sequence rule, you must publish it to make it effective for applicable entities.

You can publish a sequence rule immediately. Alternatively, if you need more time to review your rule before pushing it to entities, you can save a draft and publish the rule later.

The instructions for publishing a sequence rule immediately are described in Creating incident sequence rules. To publish a draft sequence rule, follow these steps.

How to publish an incident sequence rule draft
  1. In the FortiDLP Console, on the left-hand sidebar, click .
  2. Select the Sequence rules tab.
  3. Do one of the following:
    • To review/update the configuration prior to publishing the rule:
      1. Click the rule you want to publish.
      2. Edit the rule as needed, referring to Editing incident sequence rules and Creating incident sequence rules for instructions.
      3. Verify the Enabled toggle is turned on for all the policies you want to include in the rule stages.
      4. Verify the Operation mode toggle is set to Enabled for the rule.
      5. Note

        A rule is effective when it is enabled and published.

      6. Click Publish rule.
      7. In the Publish incident rule dialog box, click Publish.
    • To publish the rule without reviewing/updating the configuration:
      1. On the right-hand side of the row for the relevant rule, click Publish.
      2. In the Publish incident rule dialog box, click Publish.