
Administration
261
no
vd
ocx
(e
n)
7 Ja
nua
ry 201
0
11.9 Event Configuration
NOTE:
In order to use the Event Configuration, your
configuration.xml
file must be pointing to
a Communication Server that also has DAS_Binary and DAS_Query connected to it. This will
normally be the case, by default, as long as your Communication Server and DAS processes are
running.
11.9.1 Event Mapping
Event Mapping is a mechanism that allows you to add data to an event by using data already in the
event to reference and pull in data from an outside source. The outside data source is a map, which is
defined using
Map Data Configuration
. The data already in the event that should be used as the
reference into the map and the data to be pulled from the map into the event are specified using the
Events tab.
Because virtually any data set can be made into a map, Event Mapping is useful for incorporating
into the event stream data from elsewhere in your organization. Some opportunities Event Mapping
provides are:
Regulatory Compliance monitoring
Policy compliance
Response prioritization
Enable security data to be analyzed related to business operations
Enhance accountability
When an Event Mapping is defined, it is applied system-wide to all events from all Collectors.
Additionally, Sentinel will automatically distribute map data to all processes that perform event
mappings as well as keep the map data in these processes up-to-date. For these reasons, Event
Mapping provides significant capabilities to support enterprise deployments.
Event Mapping comprises of four main parts:
Controller:
Stores all map information
Distributor:
Automatically redistributes modified maps to those processes that registered for
the map
Monitor:
A monitor to detect changes in map source data
Generator:
Generates maps from source data
One application of Event Mapping is Sentinel's Asset Data functionality. For example, asset
information is collected and stored in the Sentinel Database asset schema and is represented by a
Physical Asset Entry. Soft assets, such as services and applications, are represented by an entry that
is linked to a Physical Asset. The primary automated update mechanism for asset data is through an
asset Collector reading data from a scanner such as Nmap. The asset Collector automates the
retrieval of asset information by reading asset data from the scanner and populating the asset schema
tables with this data. For Event Mapping, asset information is mapped from the destination IP and
source IP.
There are two types of data sources:
External:
A Collector populates that value in the event tag.
Содержание SENTINEL 6.1 SP2
Страница 4: ...4 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 20: ...20 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 34: ...34 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 57: ...Active Views Tab 57 novdocx en 7 January 2010 Figure 2 7 Organic View Figure 2 8 Hierarchical View ...
Страница 97: ...Incidents Tab 97 novdocx en 7 January 2010 Sort By You can set rules to sort the incidents in the display view ...
Страница 116: ...116 Sentinel 6 1 User Guide novdocx en 7 January 2010 Integer Variable String Variable ...
Страница 146: ...146 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 172: ...172 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 178: ...178 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 280: ...280 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 306: ...306 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 329: ...Quick Start 329 novdocx en 7 January 2010 ...
Страница 330: ...330 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 401: ...Sentinel Link Solution 401 novdocx en 7 January 2010 3 Select the Novell Sentinel Link Collector then click Next ...
Страница 405: ...Sentinel Link Solution 405 novdocx en 7 January 2010 6 In the Configure Connector window specify the following ...
Страница 412: ...412 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 430: ...430 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 440: ...440 Sentinel 6 1 User Guide novdocx en 7 January 2010 Figure 18 3 Reports ...
Страница 528: ...528 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...