
Sentinel Architecture
453
no
vd
ocx
(e
n)
7 Ja
nua
ry 201
0
management service to allow users to define objects using metadata. Additional services include
Correlation, Query Manager, Workflow, Event Visualization, Incident Response, Health, Advisor,
Reporting and Administration.
Figure A-8
Sentinel Logical Layers
The presentation layer renders the application interface to the end user. A comprehensive dashboard
called the Sentinel Control Center offers an integrated user workbench consisting of an array of
seven different applications accessible through a single common framework. This cross-platform
framework is built on Java
TM
1.4 standards and provides a unified view into independent business
logic components – real-time interactive graphs, actionable incident response, automated
enforceable incident workflow, reporting, incident remediation against known exploits and more.
Each of the layers are illustrated in the figure above and subsequently discussed in detail in the
following sections.
A.4.1 Collection and Enrichment Layer
Event Source Management (ESM) provides tools to manage and monitor connections between
Sentinel and third-party event sources. Events are aggregated using a set of flexible and configurable
Collectors, which collect data from a myriad of sensors and other devices and sources. User can use
pre-built Collectors, modify existing Collectors or build their own Collectors to ensure the system
meets all requirements.
Data aggregated by the Collectors in the form of events is subsequently normalized and transformed
into XML format, enriched with a series of metadata (that is, data about data) using a set of business
relevance services and propagated to the server-side for further computational analysis using
message bus platform. The Collection and Enrichment layer consists of the following components:
Connectors and Collector
Collector Manager and Engine
Collector Builder
Connectors and Collectors
A Connector is a concentrator or multiplexed adapter that connects the Collector Engine to the
actual monitored devices.
Summary of Contents for SENTINEL 6.1 SP2
Page 4: ...4 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 20: ...20 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 34: ...34 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 116: ...116 Sentinel 6 1 User Guide novdocx en 7 January 2010 Integer Variable String Variable ...
Page 146: ...146 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 172: ...172 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 178: ...178 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 280: ...280 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 306: ...306 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 329: ...Quick Start 329 novdocx en 7 January 2010 ...
Page 330: ...330 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 412: ...412 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 430: ...430 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 440: ...440 Sentinel 6 1 User Guide novdocx en 7 January 2010 Figure 18 3 Reports ...
Page 528: ...528 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...