
Administration
251
no
vd
ocx
(e
n)
7 Ja
nua
ry 201
0
11.8 Mapping
A map is a collection of values and keys defined in a CSV or text file. You can enrich your data by
using maps. With the help of maps you can add additional information to the incoming events from
your source device. This additional information which was not present can be used for correlation
and reporting.
You can create your custom maps in addition to the default maps available. You can use event
mapping which allows you to add additional data to an event by using data already present in the
event and by referencing and pulling data from an outside source. For more information, see
Section 11.9, “Event Configuration,” on page 261
and
Section 11.9.1, “Event Mapping,” on
page 261
.
NOTE:
In order to do Mapping, your
configuration.xml
file must be pointing to a
Communication Server that has DAS_Binary and DAS_Query connected to it. This will normally be
the case, by default, as long as the Communication Server and DAS processes are running.
The Mapping tab allows you to:
Add new map definitions
Edit map definitions
Delete map definitions
Update map data
Mapping works together with the Referenced from Map Data Source setting for individual fields
under
Section 11.9, “Event Configuration,” on page 261
. You can map by using a string or number
range. The following are the default maps available:
AccountIdentity:
Contains information about identities and the accounts associated with
them. The keys are UserName, UserDomain, and CustomerName (for MSSPs). This map is
populated from information in the Account and Identity tables in the Sentinel database.
Asset:
Contains the data from the map data source file
asset.csv
. The
asset.csv
is
automatically generated from asset data from Sentinel Database when an asset Collector is run.
This file could be populated manually instead, if desired. The keys are PhysicalAssetName and
CustomerName (for MSSPs).
AssetToRegulation:
Contains the data from the map data source file
AssetToRegulation.csv
. This file must be populated manually.
CustomerHierarchy:
Generally used for Managed Security Service Providers (MSSPs), this
can be used to organize customers into a four-level hierarchy Contains data from the
customerhierachy.csv. This file must be populated manually. The key is CustomerName.
IpToCountry:
Contains the data from the map data source file
IpToCountry.csv
. This file
must be populated manually.
IsExploitWatchlist:
Contains the data from the map data source file
exploitDetection.csv
(vulnerabilities and threats). The
exploitDetection.csv
file is
automatically generated from Advisor and Vulnerability data from Sentinel Database when
either an Advisor feed is completed or a vulnerability Collector is run. The keys are IP,
AttackName, DeviceName, and CustomerName (for MSSPs).
Содержание SENTINEL 6.1 SP2
Страница 4: ...4 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 20: ...20 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 34: ...34 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 57: ...Active Views Tab 57 novdocx en 7 January 2010 Figure 2 7 Organic View Figure 2 8 Hierarchical View ...
Страница 97: ...Incidents Tab 97 novdocx en 7 January 2010 Sort By You can set rules to sort the incidents in the display view ...
Страница 116: ...116 Sentinel 6 1 User Guide novdocx en 7 January 2010 Integer Variable String Variable ...
Страница 146: ...146 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 172: ...172 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 178: ...178 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 280: ...280 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 306: ...306 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 329: ...Quick Start 329 novdocx en 7 January 2010 ...
Страница 330: ...330 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 401: ...Sentinel Link Solution 401 novdocx en 7 January 2010 3 Select the Novell Sentinel Link Collector then click Next ...
Страница 405: ...Sentinel Link Solution 405 novdocx en 7 January 2010 6 In the Configure Connector window specify the following ...
Страница 412: ...412 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 430: ...430 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 440: ...440 Sentinel 6 1 User Guide novdocx en 7 January 2010 Figure 18 3 Reports ...
Страница 528: ...528 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...