Hi @Community ,
I am currently working on automating incident response workflows and need some assistance regarding the execution status of playbooks on specific alerts.
Here is my requirement:
Any help with this would be really appreciated!
Thank You!
hi @ranjeet ,
In order to solve this, we added more picklist values to the state Picklist.
Our automation starts with the state "automation started." After a playbook is successfully finished, we set the state to "automation completed." The final step won't be carried out and the alert state will be in automation started if the playbook fails.
Afterwards, we have a scheduling plan that looks for alerts that were created 15 minutes ago and that still is in automation started state with few other checks in place. If it finds any records, it updates the status to "automation failed," and you may add comments to the alert.
Regards,
Akash J
Hi @akashj,
In the case of multiple playbooks, we want to track which ones executed successfully and which ones failed.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.