
66
Sentinel 6.1 User Guide
no
vd
ocx
(e
n)
7 Ja
nua
ry 201
0
NOTE:
Events that are sent directly to the database or dropped by a Global Filter is not processed
by the Correlation Engine.
When a rule fires, a correlated event is sent to the Sentinel Control Center, where it can be viewed in
the Active Views window.
Figure 3-1
Active View window
The correlated event can also trigger actions, such as sending an email with the correlated event’s
details or creating an incident associated with an iTRAC workflow.
3.1.1 Technical Implementation
All correlation is done in-memory on the machine (or machines) that host the correlation engine.
This model allows fast, distributed processing that does not contend with database operations such
as inserting events into the database.
For environments with large numbers of correlation rules or extremely high event rates, it might be
advantageous to install more than one correlation engine and redeploy some rules to the new
correlation engine. The ability to deploy multiple correlation engines provides the ability to scale as
the Sentinel system incorporates additional data sources or as event rates increase.
Sentinel’s correlation is near real-time and depends on the timestamp for the individual events. To
synchronize time, you can use an NTP (Network Time Protocol) server to synchronize the time on
all devices on your network, or you can rely on the time on the Collector Manager servers and
synchronize only those few machines.
Correlation relies on the data that is collected, parsed, and normalized by the Collectors, so a
working understanding of the data is necessary to write rules. Many Novell correlation rules rely on
an event taxonomy that ensures that a “failed login” and an “unsuccessful logon” from two devices
are classified the same.
Содержание SENTINEL 6.1 SP2
Страница 4: ...4 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 20: ...20 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 34: ...34 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 57: ...Active Views Tab 57 novdocx en 7 January 2010 Figure 2 7 Organic View Figure 2 8 Hierarchical View ...
Страница 97: ...Incidents Tab 97 novdocx en 7 January 2010 Sort By You can set rules to sort the incidents in the display view ...
Страница 116: ...116 Sentinel 6 1 User Guide novdocx en 7 January 2010 Integer Variable String Variable ...
Страница 146: ...146 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 172: ...172 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 178: ...178 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 280: ...280 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 306: ...306 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 329: ...Quick Start 329 novdocx en 7 January 2010 ...
Страница 330: ...330 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 401: ...Sentinel Link Solution 401 novdocx en 7 January 2010 3 Select the Novell Sentinel Link Collector then click Next ...
Страница 405: ...Sentinel Link Solution 405 novdocx en 7 January 2010 6 In the Configure Connector window specify the following ...
Страница 412: ...412 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 430: ...430 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 440: ...440 Sentinel 6 1 User Guide novdocx en 7 January 2010 Figure 18 3 Reports ...
Страница 528: ...528 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...