24
Sentinel Log Manager 1.0.0.4 Administration Guide
no
vd
ocx
(e
n)
19
Fe
bru
a
ry
20
10
EventRecordID
The record ID of the corresponding event record in the event store.
NOTE:
If no event record was ever created (because of filtering) this
record ID might not point to anything.
Example: "595829C0-1C8F-102C-A922-000C2949BA91"
RawData
The original raw data received by the event source.
RawDataHash
The SHA256 hash of the RawData value represented as a HEX string.
The hash is calculated by converting the RawData value to a UTF-8
string and then performing the hash over that string.
To detect tampering, each raw data event is stored with a SHA256 hash
value.
Example:
cc661009e2f3dc565c0c7fe25b705219004dcd8132c0b0a7e987bfdcb55
e49cf
EventSourceID
The UUID of the event source the raw data came from.
Example: A2A0C600-1C6C-102C-A781-000C2949BA91
EventSourceGroupID
The UUID of the event source group (Connector) to which the event
source was connected when the raw data was received.
Example: A2A0C600-1C6C-102C-A77A-000C2949BA91
NOTE:
Different raw events from the same event source can have
different event source group IDs, because event sources can be moved
from one connector to other.
CollectorID
The UUID of the Collector that the Connector and event source were
connected to when the raw data was received.
NOTE:
Different raw events from the same event source can have
different Collector IDs, because event sources and event source groups
can be moved from one collector to another.
Example: A2A0C600-1C6C-102C-A779-000C2949BA91
EventSourceManagerID
The UUID of the Event Source Manager object where this raw data was
received.
Example: C76D2820-C395-1029-BB86-001321B5C0B3
ChainID
A random number that identifies a raw data chain. Whenever an event
source is stopped and restarted between generation of raw data events,
a new chain ID number is generated.
To detect tampering, each raw data event is stored with a Chain ID and
a Chain Sequence number.
Example: 1241630654754
Field Name
Description
Summary of Contents for SENTINEL LOG MANAGER 1.0.0.5 - 03-31-2010
Page 4: ...4 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Page 46: ...46 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Page 74: ...74 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Page 140: ...140 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Page 146: ...146 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Page 148: ...148 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Page 158: ...158 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Page 166: ...166 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Page 168: ...168 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...