
310
Sentinel 6.1 User Guide
no
vd
ocx
(e
n)
7 Ja
nua
ry 201
0
3
Click Save. Highlight your filter and click Select.
4
Provide your time period of interest; click Search (Magnifying Glass icon). The result of your
query displays. If your Event Query makes a match, you will get a result similar to the
following illustration.
If you want to see how often in general this user is attempting a telnet, remove DestinationIP,
SensorType and Severity from your filter or create a new filter. The results will show all the
destinationIPs this user is attempting to telnet to.
If any of your events are correlated events, you can right-click > View Trigger Events to find
what events triggered that correlated event.
NOTE:
Correlated events will have the SensorType column populated with a C.
More Information about Attacks
Another event of interest could be excessive FTP events. This can also be a remote connection,
allowing for transferring, copying and deleting of files.
Below is a short list of attacks of interest. Types of attacks are an extensive list. For more
information about network/host attacks, there are many resources available (that is, books and the
internet) that explain different types of attacks in detail.
14.2 Creating Incidents
NOTE:
To perform this function you must have user permission to create Incidents.
This is useful in grouping a set of events together as a whole representing something of interest
(group of similar events or set of different events that indicate a pattern of interest such as an attack).
SourceIP = 10.0.0.3
EventName = Attempted_telnet
Severity = 5
SensorType = H
DestinationIP = 10.0.0.4
Match if, select All conditions are met (and)
SYN Flood
ICMP and UDP Flood
Packet Sniffing
Denial of Service
Smurf and Fraggle
Dictionary Attack
Summary of Contents for SENTINEL 6.1 SP2
Page 4: ...4 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 20: ...20 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 34: ...34 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 116: ...116 Sentinel 6 1 User Guide novdocx en 7 January 2010 Integer Variable String Variable ...
Page 146: ...146 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 172: ...172 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 178: ...178 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 280: ...280 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 306: ...306 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 329: ...Quick Start 329 novdocx en 7 January 2010 ...
Page 330: ...330 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 412: ...412 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 430: ...430 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 440: ...440 Sentinel 6 1 User Guide novdocx en 7 January 2010 Figure 18 3 Reports ...
Page 528: ...528 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...