After upgrading from ES 8.1 to ES 8.4, automation rules are no longer functioning.
When detections are triggered based on events, playbooks should execute automatically, but they are not running. Additionally, no records are being logged in the automation history.
I would like to know how to resolve this issue.
The issue has been resolved as follows.
If you encounter the same issue, please refer to the steps below.
Root cause:
The "main" input under Settings > Data Inputs > SOAR Findings Dispatcher was disabled.
Resolution:
Enable the "main" input.
When using Automation Rules in ES, playbooks are automatically triggered through this input.
After the upgrade, this input may become disabled for an unknown reason, which can cause Automation Rules to not function properly.
The exact root cause is still under investigation.
Please take this as reference.