Actions
Actions allow you to protect your organization from the inside out. Whether a threat emerges from a user or an external cybercriminal, actions enable you to respond immediately to mitigate risk.
Actions can be performed on any managed node, firing automatically when policies are breached and on demand when initiated by operators.
Actions give you flexibility to defend against threats of different severity levels. For example, a high-risk threat may warrant blocking a managed node's inbound and outbound TCP and UDP network traffic, as well as capturing a screenshot of a user's computer screen. A medium-risk threat may require the display of a message on a user's computer screen to improve cyber hygiene. Additional actions are available to ease administration and communication. For example, you can reboot managed nodes to apply software updates.
FortiDLP supports new actions and legacy actions functionality as follows:
- Nodes running Agent 11.0.1 or later use new actions. When a new action is performed, a single event is generated and shown in the Action (New) event stream.
- Nodes running Agent 10.5.3 or earlier use legacy actions. When a legacy action is performed, multiple events are generated as the action transitions through different states. These action events are recorded in the Action (Legacy) event stream.
See the following sections to learn more: