Understand how converted event-to-actions behave
Learn how Security Center SaaS handles event-to-actions after conversion, including naming conventions, activation states, backup behavior, and execution privileges.
Naming conventions
The automations are named after the source event, the "For" condition (if any), and the action name.
Syntax: EventName (ForCondition) > ActionName
Activation state inheritance
If a converted event-to-action was deactivated before conversion, the corresponding automation created is also deactivated.
Backup and conversion behavior
The converted event-to-actions are kept as backups, but deactivated to prevent duplication of performed actions.
If an event-to-action selected for conversion remains active after conversion, it means that it cannot be converted.
Execution privileges
Automations converted from event-to-actions trigger and execute actions with the privileges of the user who performed the conversion.