Novell SENTINEL 6.1 SP2 - 02-2010 User Manual page 73

Table of Contents

Advertisement

4 Select a rule and click OK.
5 Set parameters for the rule to fire.
6 To group event tags according to the attributes, Click Add/Edit. The Attribute List window
displays.
7 Check the attribute as per your requirement. You can preview the rule in the RuleLG preview
window. Click Next. The Update Criteria window displays.
8 Update the criteria for the rule to fire and click Next. The General Description window
displays.
9 Provide a name to this rule. You have an option to modify the rule folder.
10 Provide rule description and click Next.
11 You have an option to create another rule from this wizard. Select your option and click Next.
Composite Rule
A composite rule is comprised of 2 or more subrules. A composite rule can be defined so that all or
a specified number of the subrules must fire within the defined timeframe. Composite rules have an
optional group by field, which can be any populated field from the events.
NOTE: When a subrule is used to create a composite rule, a copy of the subrule is added to the
composite rule's definition. Because a copy is added, changes to the original subrule do not affect
the composite rule.
To create a composite rule:
1 Open the Correlation Rules Manager window and select a folder from the drop-down list to
which this rule is added.
2 Click Add button located on the top left corner of the screen. The Correlation Rule window
displays. Select Composite Rule.
Correlation Tab
73

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentinel 6.1 sp2

Table of Contents