
44
Sentinel 6.1 Rapid Deployment Reference Guide
no
vd
ocx
(e
n)
13
Ma
y 20
09
3.5 Operators
Operators are used to transition between operations or expressions. The fundamental operators used
between operations are:
Flow operator
Union operator
Intersection operator
Discriminator operator
3.5.1 Flow Operator
The output set of events of the left-hand side operation is the input set of events for the right-hand
side operation. Flow is typically used to transition from one correlation operation to the next.
For example:
filter(e.sev = 5) flow trigger(3, 60)
The output of the filter operation is the input of the trigger operation. The trigger only counts events
with severity equal to 5.
3.5.2 Union Operator
The union of the left side operation output set and the right side operation output set. The resulting
output set contains events from either the left-hand side operation output set or the right-hand side
operation output set without duplicates.
For example:
filter(e.sev = 5) union filter(e.sip = 10.0.0.1)
is equivalent to
filter(e.sev = 5 or e.sip = 10.0.0.1)
3.5.3 Intersection Operator
The intersection of the left side operation output set and the right side operation output set. The
resulting output set contains events that are common in both the left-hand side operation output set
and the right-hand side operation output set without duplicates.
For example:
filter(e.sev = 5) intersection filter(e.sip = 10.0.0.1)
is equivalent to
filter(e.sev = 5 and e.sip = 10.0.0.1)
Summary of Contents for Sentinel Rapid Deployment 6.1
Page 4: ...4 Sentinel 6 1 Rapid Deployment Reference Guide novdocx en 13 May 2009 ...
Page 24: ...24 Sentinel 6 1 Rapid Deployment Reference Guide novdocx en 13 May 2009 ...
Page 36: ...36 Sentinel 6 1 Rapid Deployment Reference Guide novdocx en 13 May 2009 ...
Page 50: ...50 Sentinel 6 1 Rapid Deployment Reference Guide novdocx en 13 May 2009 ...
Page 54: ...54 Sentinel 6 1 Rapid Deployment Reference Guide novdocx en 13 May 2009 ...
Page 120: ...120 Sentinel 6 1 Rapid Deployment Reference Guide novdocx en 13 May 2009 ...
Page 124: ...124 Sentinel 6 1 Rapid Deployment Reference Guide novdocx en 13 May 2009 ...
Page 132: ...132 Sentinel 6 1 Rapid Deployment Reference Guide novdocx en 13 May 2009 ...
Page 136: ...136 Sentinel 6 1 Rapid Deployment Reference Guide novdocx en 13 May 2009 ...