
Correlation Tab
71
no
vd
ocx
(e
n)
7 Ja
nua
ry 201
0
4
Click Add to add additional definitions for this rule.
5
You can preview the rule in the RuleLG preview window. For example,
filter(e.sev=3)
.
Click Next. The Update Criteria window displays.
6
Enable the update criteria for the rule to fire and click Next. The General Description window
displays.
7
Provide a name to this rule. You have an option to modify the rule folder.
8
Provide rule description and click Next.
9
You have an option to create another rule from this wizard. Select your option and click Next.
Aggregate Rule
An aggregate rule is defined by specifying a subrule and the number of times the subrule must fire
within a specific time window in order to trigger the aggregate rule. For example, an aggregate rule
might require that a subrule fire 10 times within 5 minutes for the aggregate rule to fire.
Aggregate rules have an optional group by field, which can be any populated field from the events.
For example, an aggregate rule might require that a subrule fire 10 times within 5 minutes where
each of the 10 events has the same destination server.
NOTE:
For users familiar with the correlation rule language (RuleLG), the defining operator for an
aggregate rule is the “trigger” operator. The trigger clause might also use the “discriminator”
operator to define the group by field. For more information about RuleLG, see the “
Sentinel
Correlation Engine RuleLG Language
” in the
Sentinel 6.1 Reference Guide
.
Содержание SENTINEL 6.1 SP2
Страница 4: ...4 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 20: ...20 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 34: ...34 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 57: ...Active Views Tab 57 novdocx en 7 January 2010 Figure 2 7 Organic View Figure 2 8 Hierarchical View ...
Страница 97: ...Incidents Tab 97 novdocx en 7 January 2010 Sort By You can set rules to sort the incidents in the display view ...
Страница 116: ...116 Sentinel 6 1 User Guide novdocx en 7 January 2010 Integer Variable String Variable ...
Страница 146: ...146 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 172: ...172 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 178: ...178 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 280: ...280 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 306: ...306 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 329: ...Quick Start 329 novdocx en 7 January 2010 ...
Страница 330: ...330 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 401: ...Sentinel Link Solution 401 novdocx en 7 January 2010 3 Select the Novell Sentinel Link Collector then click Next ...
Страница 405: ...Sentinel Link Solution 405 novdocx en 7 January 2010 6 In the Configure Connector window specify the following ...
Страница 412: ...412 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 430: ...430 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 440: ...440 Sentinel 6 1 User Guide novdocx en 7 January 2010 Figure 18 3 Reports ...
Страница 528: ...528 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...