
450
Sentinel 6.1 User Guide
no
vd
ocx
(e
n)
7 Ja
nua
ry 201
0
Internal Events
Internal Events are informational and describe a single state or change of state in the system. They
report when a user logs in or fails to authenticate, when a process is started or a correlation rule is
activated.
Performance Events
Performance Events are generated on a periodic basis and describe average resources used by
different parts of the system.
Audit Events
Audit Events are generated internally. Each time an audited method is called or an audited data
object is modified, audit framework generates audit events. There are two types of Audit Events.
One which monitors user actions for example, user login/out, add/delete user and another which
monitors system actions/health, for example, process start/stop.
Some of these events used to be called Internal Events (mainly for system actions/health
monitoring). So the functionality of Audit Events is similar to Internal Events. Audit Events can be
logged into log files, saved into database, and sent out as Audit Event at the same time. (Internal
Events are only sent out as events.).
All System Events populate the following attributes:
ST (Sensor Type) field:
For internal events it is set to “I” and for performance events it is set
to “P”
Event ID:
A unique UUID for the event
Event Time:
The time the event was generated
Source:
The UUID of the process that generated the event
Sensor Name:
The name of the process that generated the event (for example, DAS_Binary)
RV32 (Device Category):
Set to “ESEC”
Collector:
“Performance” for performance events and “Internal” for internal events
In addition to the common attributes, every system event also sets the resource, sub resource, the
severity, the event name and the message tags. For internal events, the event name specific enough
to identify the exact meaning of the event (for example, UserAuthenticationFailed). The message
tags add some specific detail; in the above example the message tag will contain the name of the
user, the OS name if available and the machine name). For performance events the event name is
generic describing the type of statistical data and the data itself is in the message tag.
Performance events are sent directly to the database. To view them, do a quick query.
For more information, see
Appendix B, “System Events for Sentinel,” on page 467
.
A.3.7 Processes
The following processes and Windows service communicate with each other through iSCALE - the
message-oriented middleware (MOM).
Sentinel Service (Watchdog) (page 451)
Содержание SENTINEL 6.1 SP2
Страница 4: ...4 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 20: ...20 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 34: ...34 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 57: ...Active Views Tab 57 novdocx en 7 January 2010 Figure 2 7 Organic View Figure 2 8 Hierarchical View ...
Страница 97: ...Incidents Tab 97 novdocx en 7 January 2010 Sort By You can set rules to sort the incidents in the display view ...
Страница 116: ...116 Sentinel 6 1 User Guide novdocx en 7 January 2010 Integer Variable String Variable ...
Страница 146: ...146 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 172: ...172 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 178: ...178 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 280: ...280 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 306: ...306 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 329: ...Quick Start 329 novdocx en 7 January 2010 ...
Страница 330: ...330 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 401: ...Sentinel Link Solution 401 novdocx en 7 January 2010 3 Select the Novell Sentinel Link Collector then click Next ...
Страница 405: ...Sentinel Link Solution 405 novdocx en 7 January 2010 6 In the Configure Connector window specify the following ...
Страница 412: ...412 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 430: ...430 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 440: ...440 Sentinel 6 1 User Guide novdocx en 7 January 2010 Figure 18 3 Reports ...
Страница 528: ...528 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...