
Sentinel Architecture
455
no
vd
ocx
(e
n)
7 Ja
nua
ry 201
0
The Event Source, Event Source Server, Collector, and Connector are configuration related objects
and can be added through the ESM user interface.
Event Source:
This node represents a connection to a specific source of data, such as a
specific file, firewall or Syslog relay, and contains the configuration information necessary to
establish the connection. The health of this node represents the health of the connection to the
data source. This node will send raw data to its parent Connector node.
Event Source Server:
This node represents a deployed instance of a server-type Connector
plug-in. Some protocols, such as Syslog UDP/TCP, NAudit and others, push their data from the
source to a server that is listening to accept the data. The Event Source Server node represents
this server and can be configured to accept data from protocols that are supported by the
selected Connector plug-in. This node will redirect the raw data it receives to an Event Source
node that is configured to receive data from it.
Collector:
This node represents a deployed instance of a Collector Script. It specifies which
Collector Script to use as well as the parameter values with which the Collector should run.
This node will send Sentinel events to its parent Collector Manager node.
Connector:
This node represents a deployed instance of a Connector plug-in. It includes the
specification of which Connector plug-in to use as well as some configuration information,
such as “auto-discovery.” This node will send raw data to its parent Collector node.
Common Services
All of the above-described components in this Collection and Enrichment layer are driven by a set of
common services. These utility services form the fabric of the data collection and data enrichment
and assist in filtering the noise from the information (through global filters), applying user-defined
tags to enrich the events information (through business relevance and taxonomy mapping services)
and governing the data Collectors’ functions (through command and control services).
Taxonomy:
Nearly all security products produce events in different formats and with varying content. For
example, Windows and Solaris report a failed login differently.
Sentinel’s taxonomy automatically translates heterogeneous product data into meaningful terms,
which allows for a real-time homogeneous view of the entire network security. Sentinel Taxonomy
formats and filters raw security events before adding event context to the data stream. This process
formats all the security data in the most optimal structure for processing by the Sentinel Correlation
engine, as you can see in the following diagram.
Figure A-10
Sentinel Taxonomy
Содержание SENTINEL 6.1 SP2
Страница 4: ...4 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 20: ...20 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 34: ...34 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 57: ...Active Views Tab 57 novdocx en 7 January 2010 Figure 2 7 Organic View Figure 2 8 Hierarchical View ...
Страница 97: ...Incidents Tab 97 novdocx en 7 January 2010 Sort By You can set rules to sort the incidents in the display view ...
Страница 116: ...116 Sentinel 6 1 User Guide novdocx en 7 January 2010 Integer Variable String Variable ...
Страница 146: ...146 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 172: ...172 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 178: ...178 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 280: ...280 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 306: ...306 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 329: ...Quick Start 329 novdocx en 7 January 2010 ...
Страница 330: ...330 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 401: ...Sentinel Link Solution 401 novdocx en 7 January 2010 3 Select the Novell Sentinel Link Collector then click Next ...
Страница 405: ...Sentinel Link Solution 405 novdocx en 7 January 2010 6 In the Configure Connector window specify the following ...
Страница 412: ...412 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 430: ...430 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 440: ...440 Sentinel 6 1 User Guide novdocx en 7 January 2010 Figure 18 3 Reports ...
Страница 528: ...528 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...