Hello,
I am new to Syncro and am trying to make it so if a workstation has a firewall alert, then it should trigger a script to enable the firewall. But for some reason it is not working.
I have tried with just the Trigger category only but it didn’t work so I added the Alert body with the exact alert message but that did not work either.
I haven’t had any issues with our alerts running scripts. We have an offline alert that I haven’t seen fail and it’s just the trigger category and run script. Times like this, I wish the alerts had a “Create Automated Remediation” button.
One possible cause, if you created the remediation after the alert was created, it doesn’t remediate retroactively. You’ll have to clear the alert and wait for it to trigger again.