
Sentinel Architecture
447
no
vd
ocx
(e
n)
7 Ja
nua
ry 201
0
Figure A-5
Vulnerability and Data Source
A.3.3 Event Source Management
Sentinel 6 delivers a centralized event source management framework to facilitate data source
integration. This framework enables all aspects of configuring, deploying, managing and monitoring
data Collectors for a broad set of systems, which include databases, operating systems, directories,
firewalls, intrusion detection/prevention systems, antivirus applications, mainframes, Web and
application servers, and many more.
Using adaptable and flexible technology is central to Sentinel’s event source management strategy,
which is achieved through interpretive Collectors that parse, normalize, filter and enrich the events
in the data stream.
These Collectors can be modified as needed and are not tied to a specific environment. An
integrated development environment allows for interactive creation of Collectors using a “drag and
drop” paradigm from a graphical user interface. Non-programmers can create Collectors, ensuring
both current and future requirements are met in an ever-changing IT environment. The command
and control operation of Collectors (for example, start, stop and so on) is performed centrally from
the Sentinel Control Center. The event source management framework takes the data from the
source system, performs the transformations and presents the events for later analysis, visualization
and reporting purposes. The framework delivers the following components and benefits:
Collectors:
Parse and normalize events from various systems
Connectors:
Connect to the data source to get raw data
Taxonomy:
Allows data from disparate sources to be categorized consistently
Filtering:
Eliminates irrelevant data at the point of collection, saving bandwidth and disk
space.
Business relevance:
Offers a way to enrich event data with valuable information
Collector builder:
An Integrated Development Environment (IDE) for building custom
Collectors to collect from unique or proprietary systems
Live view:
User interface for managing live event sources.
Scratch pad:
User interface for offline design of event source configuration.
Содержание SENTINEL 6.1 SP2
Страница 4: ...4 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 20: ...20 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 34: ...34 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 57: ...Active Views Tab 57 novdocx en 7 January 2010 Figure 2 7 Organic View Figure 2 8 Hierarchical View ...
Страница 97: ...Incidents Tab 97 novdocx en 7 January 2010 Sort By You can set rules to sort the incidents in the display view ...
Страница 116: ...116 Sentinel 6 1 User Guide novdocx en 7 January 2010 Integer Variable String Variable ...
Страница 146: ...146 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 172: ...172 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 178: ...178 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 280: ...280 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 306: ...306 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 329: ...Quick Start 329 novdocx en 7 January 2010 ...
Страница 330: ...330 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 401: ...Sentinel Link Solution 401 novdocx en 7 January 2010 3 Select the Novell Sentinel Link Collector then click Next ...
Страница 405: ...Sentinel Link Solution 405 novdocx en 7 January 2010 6 In the Configure Connector window specify the following ...
Страница 412: ...412 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 430: ...430 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 440: ...440 Sentinel 6 1 User Guide novdocx en 7 January 2010 Figure 18 3 Reports ...
Страница 528: ...528 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...