
Testing the Sentinel 6.1 Rapid Deployment Installation
7
61
no
vd
ocx
(e
n)
17
Sep
te
m
be
r 20
09
7
Testing the Sentinel 6.1 Rapid
Deployment Installation
Sentinel
TM
Rapid Deployment is installed with a Generic Collector that can be used to test many of
the basic functions of the system. You can use the Collector to test Active Views, Incident creation,
Correlation rules, and Reports.
Section 7.1, “Testing the Rapid Deployment Installation,” on page 61
Section 7.2, “Cleaning Up after Testing,” on page 70
Section 7.3, “Getting Started,” on page 71
7.1 Testing the Rapid Deployment Installation
The following procedure describes the steps to test the system and the expected results. You might
not see the same events, but your results should be similar to the results below.
At a basic level, these tests allow you to confirm the following:
Sentinel Services are up and running
Communication over the message bus is functional
Internal audit events are being sent
Events can be sent from a Collector Manager
Events are inserted into the database and can be retrieved by using a report
Incidents can be created and viewed
Rules are evaluated and correlated events are triggered by the Correlation Engine
The Sentinel Data Manager is connected to the database and can read the partition information
If any of these tests fail, review the installation log and other log files, and contact
Novell Technical
Support (http://support.novell.com/phone.html?sourceidint=suplnav4_phonesup)
if necessary.
To test the installation:
1
Log in to a Sentinel 6.1 Rapid Deployment Web interface.
For more information, see “
Accessing the Novell Sentinel Web Interface
” in the
Sentinel 6.1
Rapid Deployment User Guide
.
2
Select the Search page and search for any internal event. One or more events should be
returned.
For example, to search internal events within the severity range 3-5, select
Include System
Events
, then enter
sev:[ 3 TO 5]
in the
Search
field.
For more information on Search, refer to “
Running an Event Search
” in the
Sentinel 6.1 Rapid
Deployment User Guide
.
3
Select the Reports page, specify the parameters, and run a report.
For example, click the
Run
button next to Sentinel Core Event Configuration 6.1r1, then
specify the desired parameters, and click
Run
.
Содержание Sentinel Rapid Deployment 6.1
Страница 4: ...4 Sentinel 6 1 Rapid Deployment Installation Guide novdocx en 17 September 2009 ...
Страница 8: ...8 Sentinel 6 1 Rapid Deployment Installation Guide novdocx en 17 September 2009 ...
Страница 22: ...22 Sentinel 6 1 Rapid Deployment Installation Guide novdocx en 17 September 2009 ...
Страница 72: ...72 Sentinel 6 1 Rapid Deployment Installation Guide novdocx en 17 September 2009 ...
Страница 78: ...78 Sentinel 6 1 Rapid Deployment Installation Guide novdocx en 17 September 2009 ...