
Correlation Tab
85
no
vd
ocx
(e
n)
7 Ja
nua
ry 201
0
The following instructions assume that a Dynamic List already exists.
To add a Dynamic List to correlation rule:
1
Open the Correlation Rules Manager window and select a folder from the drop-down list to
which this rule is added.
2
Click Add button located on the top left corner of the screen. The Correlation Rule window
displays. Select Custom/Freeform Rule.
3
In the Custom/Freeform Rule window, write the condition for the rule including the name of
the dynamic list. For example,
filter(e.sev inlist Severity)
where Severity is the
dynamic list name.
4
Click Validate to test the validity of the rule.
5
After validation of the rule, click Next, the Update Criteria window displays.
6
Update the criteria for the rule to fire and click Next.
7
Provide a name to this rule. You have an option to modify the rule folder.
8
Provide rule description and click Next.
9
You have an option to create another rule from this wizard. Select your option and click Next.
NOTE:
Users must have the permission to Start/Stop Correlation Engine to perform these actions.
The two states of Correlation engine are
Enable
Disable .
When the Correlation Engine is enabled, it processes active correlation Rules. When in a disabled
state, all its in-memory data is preserved and no new correlation events are generated. Disabling the
Correlation Engine does not affect other parts of the Sentinel system.
Correlation rules are stored in the Sentinel database. When you activate the Correlation Engine in
Sentinel Control Center, it requests the deployment information and rules from the database.
Changes to a rule are not reflected in the Correlation Engine until one of the following things
happens:
The rule is undeployed, edited and redeployed.
The rule is freshly deployed
3.5 Correlation Engine
Содержание SENTINEL 6.1 SP2
Страница 4: ...4 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 20: ...20 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 34: ...34 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 57: ...Active Views Tab 57 novdocx en 7 January 2010 Figure 2 7 Organic View Figure 2 8 Hierarchical View ...
Страница 97: ...Incidents Tab 97 novdocx en 7 January 2010 Sort By You can set rules to sort the incidents in the display view ...
Страница 116: ...116 Sentinel 6 1 User Guide novdocx en 7 January 2010 Integer Variable String Variable ...
Страница 146: ...146 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 172: ...172 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 178: ...178 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 280: ...280 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 306: ...306 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 329: ...Quick Start 329 novdocx en 7 January 2010 ...
Страница 330: ...330 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 401: ...Sentinel Link Solution 401 novdocx en 7 January 2010 3 Select the Novell Sentinel Link Collector then click Next ...
Страница 405: ...Sentinel Link Solution 405 novdocx en 7 January 2010 6 In the Configure Connector window specify the following ...
Страница 412: ...412 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 430: ...430 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 440: ...440 Sentinel 6 1 User Guide novdocx en 7 January 2010 Figure 18 3 Reports ...
Страница 528: ...528 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...