Create an Action Set
Focus
Focus
Device Security

Create an Action Set

Table of Contents

Create an Action Set

Build an action set that automatically runs actions when a schedule fires or an event occurs in Device Security.
Where Can I Use This?What Do I Need?
  • Device Security (Managed by Strata Cloud Manager)
One of the following subscriptions:
  • Device Security subscription
  • Precision AI bundle subscription
  • Device Security X subscription
From the Action Center at PoliciesAction Center, you can create an action set in a wizard. The wizard walks you through configuring the action set: Basic Information, Trigger, Actions, and Review. Each action set ties a trigger to a scope query and to one or more actions, so that when the trigger fires Device Security runs the actions against the assets that match the scope query.
The trigger determines when the action set runs. A schedule trigger runs the actions on a recurring cadence, an event trigger runs the actions when Device Security observes a qualifying event, and a one-time trigger only runs the actions once. The scope query narrows the set of assets the actions apply to. The main actions run first; if a main action fails and you configured a fallback action, Device Security runs the fallback action in its place.
When you confirm the action set at the end of the wizard, Device Security creates the action set in the Active state. The action set starts running the next time its trigger fires.
  1. Select PoliciesAction Center and click Create New Action Set.
    The Create Action Set wizard opens on the Basic Information step.
  2. Enter basic information for the action set.
    • Name: enter a unique name that describes what the action set does.
    • Optional Description: enter a short description of the action set's purpose for future reference.
    Action set names must be unique within your tenant. If you enter a name that is already in use, Device Security returns you to this step with the name field flagged so that you can correct it. All other wizard data is preserved.
    Click Next.
  3. Select a Trigger Type and configure when the action set runs.
    Choose Schedule to run the action set on a recurring cadence, Event to run it when Device Security observes a qualifying event, or One-Time to run it after you save the action set.
    If you choose Schedule, configure the following:
    • For Frequency, choose Daily, Weekly, or Monthly.
    • For weekly schedules, select one or more days of the week. For monthly schedules, select a day of the month.
    • For Time, enter the time of day (UTC) at which the action set runs.
    If you choose Event, choose an option from the event-type list. The action set runs each time Device Security sees the specified event that matches the scope query you configure in the next field.
    For event triggers, configure Apply Rule During to limit when the action set can fire. Enable Always to let the action set fire any time a qualifying event occurs, or clear Always and specify the time window during which the action set is allowed to fire (for example, only during business hours). Events that occur outside the configured window do not trigger the action set.
  4. Build the scope query that selects the assets the action set runs against.
    For event triggers, the action set runs only when the new event matches the scope query. For schedule triggers, the action set runs against every device that matches the scope query at the time the schedule fires.
    Click Next to continue to Actions.
  5. Add a main action.
    Click Add Action and configure the Intent → System → Outcome cascade:
    • For Intent, choose the category of action.
    • For System, choose the system that performs the action.
    • For Outcome, choose the specific action.
    Configure any outcome-specific parameters that appear — for example, for Add Custom Tag, select the tag to apply.
  6. (Optional) Add additional main actions.
    Click Add Main Action again to add another main action. All configured main actions happen when the action set's trigger fires.
  7. (Optional) Add fallback actions.
    Click Add Fall Back Action and configure the Intent → System → Outcome cascade for an action that runs if a main action fails. Use a fallback action when your primary system may be unavailable — for example, configure a Rapid7 quarantine as a fallback for a CrowdStrike isolate so that the endpoint is contained even if CrowdStrike is unreachable.
    Click Next to continue to Review & Activate.
  8. Review the configuration.
    Verify the trigger, scope query, main actions, and fallback action on the Review & Activate step. If you need to change any setting, return to the relevant wizard step.
  9. Click Confirm to create the action set.
    Device Security creates the action set in the Active state and returns you to the Action Center list page. The action set runs the next time its trigger fires. To pause or remove the action set later, see Manage Action Sets.