You can create an association between rules and those playbooks that do not require user intervention. When an event that is part of a threat has a matching rule, the associated playbook is automatically executed.
Any number of rules can be associated with a single playbook. Any number of playbooks can be associated with a single rule.
Note
You can associate only Trellix rules with playbooks. Customer rules are not currently supported.
To associate a rule with one or more playbooks:
Select Configure > Rules.
Locate the rule in the table. Then click the menu in the right column.
Select Associate Playbooks.
In the Associate Playbooks dialog box, select all playbooks or individual playbooks.
Playbooks with devices that need configuration cannot be selected. Click Fix Device Configuration to navigate to the Devices page to update the devices.
Click Associate.
To associate a playbook with one or more rules:
Select Orchestrator > Playbooks.
Click the menu at the right side of the playbook name.
Select Associate Rules.
In the Associate Rules dialog box, select all rules or individual rules.
Click Associate.
Note
To remove the association between a playbook and a rule, repeat these procedures, but clear the selected checkboxes.