Novell SENTINEL 6.1 SP2 - INSTALLATION GUIDE 02-2010 Installation Manual page 152

Hide thumbs Also See for SENTINEL 6.1 SP2 - INSTALLATION GUIDE 02-2010:
Table of Contents

Advertisement

6 What reports do you want out of the system? This is important to ensure that your Collectors
collect the correct data to be passed to the Sentinel database.
6a _______________________________________________________
6b _______________________________________________________
6c _______________________________________________________
6d _______________________________________________________
6e _______________________________________________________
6f _______________________________________________________
7 What source devices do you want to collect data from (IDS, HIDS, Routers, Firewalls and so
on), event rate (EPS – events per second), versions, connection methods, platforms and
patches?
Device (mfr/
model)
Can you provide sample data of what you want the Sentinel Collectors to collect and parse?
Sentinel can be configured to provide the desired output based on the information provided
here.
8 What security model/standards exist at your site?
What is your stance on local accounts versus domain authentication?
9 What is the required data retention in terms of days?
10 Based on the data retention information and EPS, what disk size will you be using? Use 500 to
800 bytes/event for sizing estimates.
11 What event patterns do you want to identify in your data?
12 Does the current data available from your event sources support the event patterns you want to
detect, or will event enrichment using the mapping service be needed?
13 If the mapping service is needed, what is the source of the enrichment data, and what key will
be used to perform the mapping? How will the maps be kept up to date?
14 When a security or compliance violation is detected, what processes will be used to remediate?
152 Sentinel 6.1 Installation Guide
Event Rate
Version
(EPS)
For Windows with domain authentication, proper domain account settings must be
created to ensure that Sentinel can be installed.
For Solaris install, this is not applicable. However, Sentinel does not support NIS.
Connection
Platform
Method
Patches

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentinel 6.1 sp2

Table of Contents