Playbook event trigger correleation rules 7.4.1
This information is also available in the FortiAnalyzer 7.4 Administration Guide: |
FortiAnalyzer v7.4.1 introduces extra flexibility on playbooks by implementing:
-
Option to select Any of the following conditions (OR): The event is triggered if any of the defined conditions are met.
-
Nested groups: Conditions can be grouped together and linked by either AND or OR.
When creating a playbook in Fabric View > Automation > Playbook, the EVENT_TRIGGER configuration includes options to Add Condition and Add Condition Group.
When adding a condition, you can select one of the following:
-
All of the following conditions (AND)
-
Any of the following conditions (OR)
The conditions can be nested in groups. For example, "(group1 AND group2) OR (group3)". See below.