Fortinet white logo
Fortinet white logo

User Guide

Adding a playbook to an investigation

Adding a playbook to an investigation

To add a playbook to an investigation:
  1. Go to Investigations > Investigate.

  2. Open the investigation you want to add a playbook to.

  3. Click the Add Playbook button.. Alternatively, click on Add menu (+) in the top-right corner of the page and select Add Playbook. The Playbook Library opens.

  4. Click Select to select a playbook from the library or click the playbook name.

  5. Configure the playbook settings.
    Date rangeUse the date picker to configure the date range.
    Enable FacetsSelect to return the panel that allows narrowing the search. This may make the query longer to complete. For more information, see Facet Search.
    Variables

    Enter the required variable(s) for the queries. Multiple variables are supported.

    Values can be entered either as:

    • Individual items, followed by the tab or enter key. The value appears as a pill that can then be deleted, if required.

    • Bulk indicator icon. This brings up an entry screen. Pasting the text is supported. After pressing the button, FortiNDR Cloud extracts the applicable indicators from the text and adds them as variables. You can also delete the unneeded variables.

    Create a New Investigation

    Select this option to create a new investigation. Enter the Investigation Name and Description.

    The default name for new investigations is the first and last name of the user creating the investigation as well as a date stamp of when the investigation was created.

    Add to Existing Investigation

    From the Choose Investigation dropdown, select and investigation.

  6. Click Run Playbookk.

Adding a playbook to an investigation

Adding a playbook to an investigation

To add a playbook to an investigation:
  1. Go to Investigations > Investigate.

  2. Open the investigation you want to add a playbook to.

  3. Click the Add Playbook button.. Alternatively, click on Add menu (+) in the top-right corner of the page and select Add Playbook. The Playbook Library opens.

  4. Click Select to select a playbook from the library or click the playbook name.

  5. Configure the playbook settings.
    Date rangeUse the date picker to configure the date range.
    Enable FacetsSelect to return the panel that allows narrowing the search. This may make the query longer to complete. For more information, see Facet Search.
    Variables

    Enter the required variable(s) for the queries. Multiple variables are supported.

    Values can be entered either as:

    • Individual items, followed by the tab or enter key. The value appears as a pill that can then be deleted, if required.

    • Bulk indicator icon. This brings up an entry screen. Pasting the text is supported. After pressing the button, FortiNDR Cloud extracts the applicable indicators from the text and adds them as variables. You can also delete the unneeded variables.

    Create a New Investigation

    Select this option to create a new investigation. Enter the Investigation Name and Description.

    The default name for new investigations is the first and last name of the user creating the investigation as well as a date stamp of when the investigation was created.

    Add to Existing Investigation

    From the Choose Investigation dropdown, select and investigation.

  6. Click Run Playbookk.