
Sentinel Architecture
A
441
no
vd
ocx
(e
n)
7 Ja
nua
ry 201
0
A
Sentinel Architecture
Sentinel is a security information and event management (SIEM) solution that automates the
collection, analysis and reporting of system network, application and security logs to help
organizations manage IT risk.
This section discusses the functional and technical architecture of Sentinel.
Section A.1, “Sentinel Features,” on page 441
Section A.2, “Functional Architecture,” on page 441
Section A.3, “Architecture Overview,” on page 442
Section A.4, “Logical Architecture,” on page 452
A.1 Sentinel Features
Sentinel allows you to monitor and manage a variety of functions. Some of the main functions
include:
Real-time views of large streams of events
Reporting capabilities based on real-time and historical events
Managing users and what they are able to see and do by permission assignment
Managing access to events for different users
Organizing events into incidents for efficient response management and tracking
Detecting patterns in events and streams of events
An intuitive and flexible rule-based language for correlation
Rules compiled for high performance
Scalable, multi-threaded, distributable, and extensible architecture
Sentinel processes communicate with each other through a message-oriented middleware (MOM).
A.2 Functional Architecture
Sentinel is composed of the following component subsystems, which form the core of the functional
architecture:
Section A.3.1, “iSCALE Platform,” on page 442
: An event-driven scalable framework.
Section A.3.3, “Event Source Management,” on page 447
: An extensible framework built to
manage and monitor connections between Sentinel and third-party event sources, using
Sentinel Connectors and Sentinel Collectors.
In addition to ESM, there are a number of subcomponents that are hosted by a distributable
service called the Collector Manager. This service can be installed on a number of systems to
balance the processing load or for scalability. The data collection components are downloaded
from the Novell Content Web page and are installed to the Collector Managers via a central
ESM interface.
Section A.3.4, “Application Integration,” on page 448
: An extensible application framework.
Содержание SENTINEL 6.1 SP2
Страница 4: ...4 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 20: ...20 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 34: ...34 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 57: ...Active Views Tab 57 novdocx en 7 January 2010 Figure 2 7 Organic View Figure 2 8 Hierarchical View ...
Страница 97: ...Incidents Tab 97 novdocx en 7 January 2010 Sort By You can set rules to sort the incidents in the display view ...
Страница 116: ...116 Sentinel 6 1 User Guide novdocx en 7 January 2010 Integer Variable String Variable ...
Страница 146: ...146 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 172: ...172 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 178: ...178 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 280: ...280 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 306: ...306 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 329: ...Quick Start 329 novdocx en 7 January 2010 ...
Страница 330: ...330 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 401: ...Sentinel Link Solution 401 novdocx en 7 January 2010 3 Select the Novell Sentinel Link Collector then click Next ...
Страница 405: ...Sentinel Link Solution 405 novdocx en 7 January 2010 6 In the Configure Connector window specify the following ...
Страница 412: ...412 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 430: ...430 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 440: ...440 Sentinel 6 1 User Guide novdocx en 7 January 2010 Figure 18 3 Reports ...
Страница 528: ...528 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...