
Sentinel Architecture
461
no
vd
ocx
(e
n)
7 Ja
nua
ry 201
0
Figure A-14
Process Template
A worklist provides the user with all tasks that have been assigned to the user and a process monitor
provides real-time visibility into process status during a resolution process lifecycle.
iTRAC’s activity framework enables users to customize automated or manual tasks for specific
incident-resolution processes. The iTRAC process templates can be configured using the activity
framework to match the template with an organization’s best practices. Activities are executed
directly from the Sentinel Control Center.
iTRAC’s automation framework works using two key components:
Activity container
It automates the activities execution for the specified set of steps based on input rules
Workflow container
It automates the workflow execution based on activities through a work-list.
The input rules are based on the XPDL (XML Processing Description Language) standard and
provide a formal model for expressing executable processes in a business enterprise. This standards-
based approach to the implementation of business-specific rules and rule sets ensures future-
proofing of process definitions for customers.
The iTRAC system uses three Sentinel 6 objects that can be defined outside the iTRAC framework:
Incident:
Incidents within Sentinel 6 are groups of events that represent an actionable security
incident, associated state and meta-information. Incidents are created manually or through
correlation rules, and can be associated with a workflow process. They can be viewed on the
Incidents tab.
Activity:
An Activity is a pre-defined automatic unit of work, with defined inputs, command-
driven activity and outputs, such as automatic attachment of asset data to the incident or
generation of an e-mail. Activities can be used within workflow templates, triggered by a
correlation rule, or executed by a right-click when viewing events.
Содержание SENTINEL 6.1 SP2
Страница 4: ...4 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 20: ...20 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 34: ...34 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 57: ...Active Views Tab 57 novdocx en 7 January 2010 Figure 2 7 Organic View Figure 2 8 Hierarchical View ...
Страница 97: ...Incidents Tab 97 novdocx en 7 January 2010 Sort By You can set rules to sort the incidents in the display view ...
Страница 116: ...116 Sentinel 6 1 User Guide novdocx en 7 January 2010 Integer Variable String Variable ...
Страница 146: ...146 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 172: ...172 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 178: ...178 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 280: ...280 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 306: ...306 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 329: ...Quick Start 329 novdocx en 7 January 2010 ...
Страница 330: ...330 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 401: ...Sentinel Link Solution 401 novdocx en 7 January 2010 3 Select the Novell Sentinel Link Collector then click Next ...
Страница 405: ...Sentinel Link Solution 405 novdocx en 7 January 2010 6 In the Configure Connector window specify the following ...
Страница 412: ...412 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 430: ...430 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 440: ...440 Sentinel 6 1 User Guide novdocx en 7 January 2010 Figure 18 3 Reports ...
Страница 528: ...528 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...