Kaspersky Next XDR Expert allows you to manually launch all playbooks that match all alerts or incidents you want to respond to.
To launch a playbook manually, you must have one of the following roles: Main administrator, Junior analyst, Tier 1 analyst, Tier 2 analyst, Tenant administrator.
To launch a playbook manually for an alert:
The Select playbook window opens.
If the selected playbook is already running for this alert, in the Monitoring & reporting window that appears, do one of the following:
The new playbook instance will be launched after the current one is completed.
The current playbook instance will be terminated and the new one will be launched.
If the selected playbook already has the status Awaiting approval, after manual launch, the playbook status will change to In progress.
The playbook is launched for the selected alert. After the playbook is completed, you will receive a notification.
To launch a playbook manually for an incident:
The Select playbook window opens.
If the selected playbook is already running for this incident, in the Monitoring & reporting window that appears, do one of the following:
The new playbook instance will be launched after the current one is completed.
The current playbook instance will be terminated and the new one will be launched.
If the selected playbook already has the status Awaiting approval, after manual launch, the playbook status will change to In progress.
The playbook is launched for the selected incident. After the playbook is completed, you will receive a notification.
Page top