Novell SENTINEL 6.1 SP2 - 02-2010 User Manual page 74

Table of Contents

Advertisement

3 In Composite Rule window, you can select sub-rules to create a composite rule. To select a sub-
rule, click Add Rule button. Add Rule window displays.
4 Select a rule or a set of rules (hold control on your keyboard to select a set of rules) and click
OK.
5 Set parameters for the rule to fire.
6 To group event tags according to the attributes, Click Add/Edit. The Attribute window
displays.
7 Check the attribute as per your requirement. You can preview the rule in RuleLg preview box.
Click Next, the Update Criteria window displays.
8 Update criteria for the rule to fire and click Next.
9 Provide a name to this rule. You have an option to modify the rule folder.
10 Provide rule description and click Next.
11 You have an option to create another rule from this wizard. Select your option and click Next.
Sequence
A sequence rule is comprised of 2 or more subrules that must have been triggered in a specific order
within the defined timeframe. Sequence rules have an optional group by field, which can be any
populated field from the events.
NOTE: When a subrule is used to create a sequence rule, a copy of the subrule is added to the
sequence rule's definition. Because a copy is added, changes to the original subrule do not affect the
sequence rule.
74
Sentinel 6.1 User Guide

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentinel 6.1 sp2

Table of Contents