
452
Sentinel 6.1 User Guide
no
vd
ocx
(e
n)
7 Ja
nua
ry 201
0
Data Access Service (DAS) Process
The Data Access Service (DAS) process is Sentinel Server's persistence service and provides an
interface to the database. It provides data driven access to the database backend.
DAS is a container, composed of five different processes. Each process is responsible for different
types of database operations. These processes are controlled by the following configuration files:
das_binary.xml:
Used for event and correlated event insertion operations
das_query.xml:
All other database operations
activity_container.xml:
Used for executing and configuring activity service
workflow_container.xml:
Used for configuring the workflow (iTRAC) service
das_rt.xml:
Used for configuring the Active Views function within the Sentinel Control
Console
DAS receives requests from the different Sentinel processes, converts them to a query against the
database, processes the result from the database and converts it that back to a reply. It supports
requests to retrieve events for Quick Query and Event Drill Down, to retrieve vulnerability
information and advisor information and to manipulate configuration information. DAS also handles
logging of all events being received from the Collector Manager and requests to retrieve and store
configuration information.
Correlation Engine Process (correlation_engine)
The Correlation Engine (correlation_engine) process receives events from the Collector Manager
and publishes correlated events based on user-defined correlation rules.
Collector Manager
Collector Manager services, processes and sends events.
iSCALE
It is a message-oriented middleware (MOM) that provides the communication platform for all other
Sentinel processes.
A.4 Logical Architecture
Sentinel is composed of three logical layers:
Section A.4.1, “Collection and Enrichment Layer,” on page 453
Section A.4.2, “Business Logic Layer,” on page 456
Section A.4.3, “Presentation Layer,” on page 464
The collection/enrichment layer aggregates the events from external data sources, transforms the
device-specific formats into Sentinel format, enriches the native events source with business-
relevant data and dispatches the event packets to the message bus. The key component orchestrating
this function is the Collector, aided by a taxonomy mapping and global filter service.
The business logic layer contains a set of distributable components. The base component is a
Remoting service that adds messaging capabilities to the data objects and services to enable
transparent data access across the entire network and Data Access service that is an object
Содержание SENTINEL 6.1 SP2
Страница 4: ...4 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 20: ...20 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 34: ...34 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 57: ...Active Views Tab 57 novdocx en 7 January 2010 Figure 2 7 Organic View Figure 2 8 Hierarchical View ...
Страница 97: ...Incidents Tab 97 novdocx en 7 January 2010 Sort By You can set rules to sort the incidents in the display view ...
Страница 116: ...116 Sentinel 6 1 User Guide novdocx en 7 January 2010 Integer Variable String Variable ...
Страница 146: ...146 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 172: ...172 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 178: ...178 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 280: ...280 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 306: ...306 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 329: ...Quick Start 329 novdocx en 7 January 2010 ...
Страница 330: ...330 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 401: ...Sentinel Link Solution 401 novdocx en 7 January 2010 3 Select the Novell Sentinel Link Collector then click Next ...
Страница 405: ...Sentinel Link Solution 405 novdocx en 7 January 2010 6 In the Configure Connector window specify the following ...
Страница 412: ...412 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 430: ...430 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 440: ...440 Sentinel 6 1 User Guide novdocx en 7 January 2010 Figure 18 3 Reports ...
Страница 528: ...528 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...