
16
Sentinel 6.1 Rapid Deployment Reference Guide
no
vd
ocx
(e
n)
13
Ma
y 20
09
Table 1-1
Labels and Meta-tags used in Sentinel Control Center and proprietary Collector language
Default Label
Filters and
Correlation
Rules
Menu and
Correlation
Actions
Proprietary
Collector
Language
Data
Type
Description
DeviceEventTimeString
e.et
%et%
s_ET
string
The normalized date and
time of the event, as
reported by the sensor.
DeviceEventTime
e.det
%det%
date
The normalized date and
time of the event, as
reported by the sensor.
SentinelProcessTime
e.spt
%spt%
date
The date and time
Sentinel received the
event.
BeginTime
e.bgnt
%bgnt%
s_BGNT
date
The date and time the
event started occurring
(for repeated events).
EndTime
e.endt
%endt%
s_ENDT
date
The date and time the
event stopped occurring
(for repeated events).
RepeatCount
e.rc
%rc%
s_RC
integer
The number of times the
same event occurred if
multiple occurrences were
consolidated.
EventTime
e.dt
%dt%
date
The normalized date and
time of the event, as given
by the Collector.
SentinelServiceID
e.src
%src%
UUID
Unique identifier for the
Sentinel service which
generated this event.
Severity
e.sev
%sev%
i_Severity
integer
The normalized severity
of the event (0-5).
Vulnerability
e.vul
%vul%
s_VULN
integer
The vulnerability of the
asset identified in this
event. Set to 1 if Sentinel
detects an exploit against
a vulnerable system.
Requires Advisor.
Criticality
e.crt
%crt%
s_CRIT
integer
The criticality of the asset
identified in this event.
InitIP
e.sip
%sip%
s_SIP
IPv4
IPv4 address of the
initiating system.
TargetIP
e.dip
%dip%
s_DIP
IPv4
IPv4 address of the target
system.
Collector
e.port
%port%
string
Name of the Collector that
generated this event.
Summary of Contents for Sentinel Rapid Deployment 6.1
Page 4: ...4 Sentinel 6 1 Rapid Deployment Reference Guide novdocx en 13 May 2009 ...
Page 24: ...24 Sentinel 6 1 Rapid Deployment Reference Guide novdocx en 13 May 2009 ...
Page 36: ...36 Sentinel 6 1 Rapid Deployment Reference Guide novdocx en 13 May 2009 ...
Page 50: ...50 Sentinel 6 1 Rapid Deployment Reference Guide novdocx en 13 May 2009 ...
Page 54: ...54 Sentinel 6 1 Rapid Deployment Reference Guide novdocx en 13 May 2009 ...
Page 120: ...120 Sentinel 6 1 Rapid Deployment Reference Guide novdocx en 13 May 2009 ...
Page 124: ...124 Sentinel 6 1 Rapid Deployment Reference Guide novdocx en 13 May 2009 ...
Page 132: ...132 Sentinel 6 1 Rapid Deployment Reference Guide novdocx en 13 May 2009 ...
Page 136: ...136 Sentinel 6 1 Rapid Deployment Reference Guide novdocx en 13 May 2009 ...