![Novell SENTINEL LOG MANAGER 1.0.0.5 - 03-31-2010 Скачать руководство пользователя страница 111](http://html1.mh-extra.com/html/novell/sentinel-log-manager-1-0-0-5-03-31-2010/sentinel-log-manager-1-0-0-5-03-31-2010_administration-manual_1711904111.webp)
Configuring Rules
7
111
no
vd
ocx
(e
n)
19
Fe
bru
a
ry
20
10
7
Configuring Rules
You can configure rules to evaluate and filter all incoming events and deliver selected events to
designated output channels. For example, each severity 5 event can be e-mailed to a security analyst
distribution list or to an administrator.
This section describes the event channels and rules that can be used to send events from Novell
®
Sentinel
TM
Log Manager to another system.
Section 7.1, “Configuring Rules,” on page 111
Section 7.2, “Configuring Actions,” on page 114
Section 7.3, “Configuring E-Mail Notification of Auto-Created Event Sources without a Time
Zone,” on page 125
Section 7.4, “Forwarding the Events to Another Sentinel System,” on page 127
7.1 Configuring Rules
Sentinel Log Manager rules can be configured to filter events based on one or more of the
searchable fields. Each rule can be associated with one or more of the configured actions.
The rules are evaluated on a first-match basis in top-down order and the first matched rule is applied
to the events that matches the filter criteria.
Section 7.1.1, “Filter Criteria,” on page 111
Section 7.1.2, “Adding a Rule,” on page 111
Section 7.1.3, “Editing a Rule,” on page 112
Section 7.1.4, “Ordering Rules,” on page 112
Section 7.1.5, “Deleting a Rule,” on page 113
Section 7.1.6, “Activating or Deactivating a Rule,” on page 113
7.1.1 Filter Criteria
Rules can be based on any searchable event field. The available operators depend on the data type of
the event field. For example, match subnet is available for IP addresses, and match regex is available
for text fields.
7.1.2 Adding a Rule
You can add a filter-based rule and then define one or more channels where you want to output the
events that meet the rule criteria.
1
Log in to the Sentinel Log Manager as an administrator.
2
Click
rules
in the upper left corner of the page.
The
Rules
tab is displayed on the right pane of the page.
3
Click
Add Rule
.
Содержание SENTINEL LOG MANAGER 1.0.0.5 - 03-31-2010
Страница 4: ...4 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Страница 46: ...46 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Страница 74: ...74 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Страница 140: ...140 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Страница 146: ...146 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Страница 148: ...148 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Страница 158: ...158 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Страница 166: ...166 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...
Страница 168: ...168 Sentinel Log Manager 1 0 0 4 Administration Guide novdocx en 19 February 2010 ...