Configuring automation responses

2026-09-01Last updated

To define what happens when an automation is triggered, you must add response actions to the automation.

What you should know

Navigation diagram showing step 3 of 5.

Procedure

  1. Select the automation and click the Properties tab.
  2. (Optional) To add a delay between an action and its response:
    1. Next to the Add an action button, click the down arrow.
    2. Select Add a delay and enter the delay in hours, minutes, and seconds.
    3. Click OK.
  3. In the Response section, click Add an item ().
    Some events support an acknowledgment condition when you configure an alarm as a response. This condition must be met before the alarm can be acknowledged.
  4. (Optional) Contextualize your actions by using arguments based on the data from the event that triggered the automation. For a full list of available actions, see Action types.
    Note:
    Actions previously reserved for threat levels can also be used in automation responses, except when applying an action to All entities. For more information, see Threat level actions.
  5. (Optional) To run an automation as a response to another automation, add the Run an automation action.
  6. Select an action type and set its arguments.
  7. Add additional actions as required.
  8. Click Apply.
The automation is configured.

After you finish

If the configuration is complete, right-click the automation in the entity tree and click Activate (). If it is incomplete, configure the advanced settings.