Manage playbook triggers
An ingestion trigger defines the initial conditions that cause a playbook to attach automatically when a new alert or case enters the system. You configure these triggers during the initial phase of building a playbook.
To view your options, open the Triggers menu and select the Ingestion tab.
Available ingestion triggers
The options on the Ingestion tab dynamically change based on the scope you choose when setting up the playbook.
Alert scope ingestion triggers
When you configure a playbook with an Alert scope, you can choose from these options:
- All: Triggers the playbook for every alert generated in your environment.
- Alert Type: Triggers based on the Rule Generator field configured during connector setup. For details, see Configure the connector.
- Product Name: Triggers when an alert comes from a specific product or connector.
- Alert Trigger Value: Triggers based on a predefined field from the connector. We recommend using Custom Trigger instead.
- Custom Trigger: Triggers based on custom placeholders for specific matches.
- Custom List: Triggers based on a predefined custom list in your settings.
- Network Name: Triggers if an alert involves an entity within a defined subnet.
Case scope ingestion triggers
When you configure a playbook with a Case scope, the menu filters down to these options:
- All: Attaches the playbook to every newly created case.
- Custom trigger: Attaches the playbook based on specific filtering rules you define.
For event-based and lifecycle triggers that fire during an active investigation, see Use reaction triggers in playbooks.
Add an ingestion trigger to a playbook
To add an ingestion trigger to your workflow, follow these steps:
- Create a new playbook. For details, see Create and edit a playbook with Gemini.
- In the playbook creation dialog, select your playbook Scope (Alert or Case) to load the correct trigger set, then click Create.
- On the Step Selection menu, select Triggers.
- Select the Ingestion tab, choose a trigger, and drag it to the first step box on the playbook canvas.
- Double-click the trigger icon on the canvas to open the parameters side drawer.
- Under Parameters, define your evaluation criteria (such as Equal, Contains, or Starts With) and enter the target value for your automation rules.
After you save your changes, the parameter details appear directly in the trigger description on the canvas.
You can now continue building the playbook with actions. For more information, see Manage actions in playbooks.
Need more help? Get answers from Community members and Google SecOps professionals.