Novell SENTINEL 6.1 SP2 - 02-2010 User Manual page 71

Table of Contents

Advertisement

4 Click Add to add additional definitions for this rule.
5 You can preview the rule in the RuleLG preview window. For example,
Click Next. The Update Criteria window displays.
6 Enable the update criteria for the rule to fire and click Next. The General Description window
displays.
7 Provide a name to this rule. You have an option to modify the rule folder.
8 Provide rule description and click Next.
9 You have an option to create another rule from this wizard. Select your option and click Next.
Aggregate Rule
An aggregate rule is defined by specifying a subrule and the number of times the subrule must fire
within a specific time window in order to trigger the aggregate rule. For example, an aggregate rule
might require that a subrule fire 10 times within 5 minutes for the aggregate rule to fire.
Aggregate rules have an optional group by field, which can be any populated field from the events.
For example, an aggregate rule might require that a subrule fire 10 times within 5 minutes where
each of the 10 events has the same destination server.
NOTE: For users familiar with the correlation rule language (RuleLG), the defining operator for an
aggregate rule is the "trigger" operator. The trigger clause might also use the "discriminator"
operator to define the group by field. For more information about RuleLG, see the
Correlation Engine RuleLG
Language" in the
Sentinel 6.1 Reference
filter(e.sev=3)
"Sentinel
Guide.
Correlation Tab
.
71

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentinel 6.1 sp2

Table of Contents