Select Response > Response Actions to open the Response Actions page. To add a response action, click Add. To edit a response action, click the response action name or select Edit from the menu at the end of the row.
The dialog box that opens contains three sections:
General. Name and describe the response action, associate a playbook with it, and select a theme of red or gray. The theme determines which Fix Now menu will include the response action. Critical response actions typically have the red theme, and routine response actions typically have the gray theme.
Associated Rules. Click Add Rules and select the rule or rules that trigger the playbook when an event matches the rule.
Artifacts Required. View the artifacts relevant to the playbook that is mapped to the response action. This section shows the artifact name, input type (such as string), whether the artifact is mandatory, and whether it is a list.
The following shows an example response action.
.png)