Event Query - Novell SENTINEL 6.1 SP2 - 02-2010 User Manual

Table of Contents

Advertisement

Asset Report
Figure 14-1

14.1.4 Event Query

This section talks about event query
Example Scenario – Telnet Event:
During monitoring, you see numerous telnet attempts from source IP 10.0.0.1 Telnet attempts could
be an attack. Telnet potentially allows an attacker to remotely connect to a remote computer as if
they were locally connected. This can lead to unauthorized configuration changes, installation of
programs, viruses, and so on.
You can Event Query to determine how often this possible attacker has attempted a telnet; you can
setup a filter to query for this particular attacker. For example, you know the following:
Source IP: 10.0.0.1
Destination IP: 10.0.0.2
Severity: 5
To Perform an Event Query:
1 In the Sentinel Control Center, click Event Query (Magnifying Glass icon) and click the Filter
drop-down menu.
2 A window with a list of filters displays. Click Add; specify a filter name of telnet SIP 10.0.0.1.
In the field below the Filter, specify:
Event Name: Attempted_telnet
Sensor Type: H (Host Intrusion Detection)
Quick Start 309

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentinel 6.1 sp2

Table of Contents