
302
Sentinel 6.1 User Guide
no
vd
ocx
(e
n)
7 Ja
nua
ry 201
0
4
If cleaning Incidents, the following things happen:
4a
The following prompt displays:
Would you like to backup Incidents first? (y or n) =>
Enter "y" to backup the Incident data (recommended) or "n" to skip the
Incident data backup.
4b
If you select “y” to back up the Incidents, enter the destination directory (a full path or a
path relative to the location of the cleanup script) for the backup files.
NOTE:
The user running the script must have permission to write to this directory.
4c
You will be prompted again to enter the password for the database user previously
specified
NOTE:
This prompt is necessary to prevent passing the password via the command line
to the database exp command and making the password possibly visible in "ps"
commands.
4d
The .dmp files and a log file are created in the specified backup directory.
4e
Choose an Incident cleanup option:
(1) Delete Incidents By Query – You will be prompted to enter a custom SELECT query.
For example:
select inc_id from incidents where inc_id=500
NOTE:
The SELECT statement cannot include quotation marks.
(2) Delete Incidents By Rule – You will be prompted to enter the name of the Correlation
Rule(s) that created the Incident(s) For example:
My Test Rule
(3) Delete Incidents By Id – You will be prompted to enter the ID of a specific Incident.
For example:
101
(q) Quit without action
4f
At the Incident Cleanup Confirmation prompt, type "start" to start the Incident cleanup
(deletion) or "abort" to quit without performing any cleanup.
4g
The results of the Incident Cleanup will be written to the specified log file.
NOTE:
You should review the log file for any errors before continuing.
5
If cleaning Identity, the following things happen:
5a
At the Identity Cleanup Confirmation prompt, type "start" to start the Identity cleanup or
"abort" to quit without performing the Identity cleanup.
5b
The results of the Identity Cleanup will be written to the specified log file.
NOTE:
You should review the log file for any errors before continuing.
5c
In addition to deleting the Identity information from the database tables, the script will
attempt to delete the Identity Account Map file (identityAccountMap.csv). So at the
prompt
Please enter the esecadm user password =>
Summary of Contents for SENTINEL 6.1 SP2
Page 4: ...4 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 20: ...20 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 34: ...34 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 116: ...116 Sentinel 6 1 User Guide novdocx en 7 January 2010 Integer Variable String Variable ...
Page 146: ...146 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 172: ...172 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 178: ...178 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 280: ...280 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 306: ...306 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 329: ...Quick Start 329 novdocx en 7 January 2010 ...
Page 330: ...330 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 412: ...412 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 430: ...430 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 440: ...440 Sentinel 6 1 User Guide novdocx en 7 January 2010 Figure 18 3 Reports ...
Page 528: ...528 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...