Novell SENTINEL 6.1 SP2 - 02-2010 User Manual page 77

Table of Contents

Advertisement

Field Name
Message
Resource
SubResource
Other types of actions can be configured in the Action Manager:
Configure a Correlated Event (replaces the default correlated event settings)
Add to Dynamic List (adds an element to a dynamic list)
Remove from Dynamic List (removes an element from a dynamic list)
Execute a Command (executes a shell or batch script)
Execute a Script (executes a script; only available for actions created in Sentinel 6.0)
Send an Email (using default Sentinel mail settings)
Create an Incident (creates a Sentinel incident)
Any Action configured in the Action Manager that was created from an Action plugin that
takes a Correlated Event as input. For more information on
Chapter 16, "Actions and Integrator," on page
To deploy Correlation Rules (in Correlation Engine Manager):
1 Open the Correlation Engine Manager window.
2 Highlight and right-click the engine you want to deploy the rule on and select Deploy Rule.
3 In the Rules tab, select the rule or rules you want to deploy.
4 In the Actions tab, select the action or actions you want to associate with the rule.
Default Values
Same as the message for the trigger event
Correlation
<Rule Name>
365.
Action Manager (page
366), see the
Correlation Tab
77

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentinel 6.1 sp2

Table of Contents