Fortinet black logo

User Guide

Running a playbook of event records

Running a playbook of event records

To run a playbook of event records:
  1. Go to t Investigations > Investigate.

  2. Select an investigation from the list.

  3. Click View Results to view the investigation results.

  4. Right click on an entity to open the context menu and select Playbooks.

    Playbooks

  5. Select a playbook from the list.

    If the event record has matching variables in the playbook, then the variables will be populated with values from the event record.

    Playbook EventRecords2

  6. Add or modify the values for the variables. For information see, Facet Search.

  7. Create a new investigation or add the playbook to an investigation.
    Create a New Investigation

    Select this option to create a new investigation. Enter the Investigation Name and Description.

    The default name for new investigations is the first and last name of the user creating the investigation as well as a date stamp of when the investigation was created.

    Add to Existing Investigation

    From the Choose Investigation dropdown, select and investigation.

  8. Click Run Playbook.

Running a playbook of event records

To run a playbook of event records:
  1. Go to t Investigations > Investigate.

  2. Select an investigation from the list.

  3. Click View Results to view the investigation results.

  4. Right click on an entity to open the context menu and select Playbooks.

    Playbooks

  5. Select a playbook from the list.

    If the event record has matching variables in the playbook, then the variables will be populated with values from the event record.

    Playbook EventRecords2

  6. Add or modify the values for the variables. For information see, Facet Search.

  7. Create a new investigation or add the playbook to an investigation.
    Create a New Investigation

    Select this option to create a new investigation. Enter the Investigation Name and Description.

    The default name for new investigations is the first and last name of the user creating the investigation as well as a date stamp of when the investigation was created.

    Add to Existing Investigation

    From the Choose Investigation dropdown, select and investigation.

  8. Click Run Playbook.