Incidents Tab; Understanding An Incident; Introduction To User Interface - Novell SENTINEL 6.1 SP2 - 02-2010 User Manual

Table of Contents

Advertisement

Incidents Tab

4
Section 4.1, "Understanding an Incident," on page 93
Section 4.2, "Introduction to User Interface," on page 93
Section 4.3, "Manage Incident Views," on page 95
Section 4.4, "Manage Incidents," on page 99
Section 4.5, "Switch between existing Incident Views," on page 106

4.1 Understanding an Incident

In Sentinel, a set of related events (for example, a possible attack) can be grouped together form an
Incident. An Incident in "open" state alerts you to investigate, resolve, and close the incident. For
example, the resolution to an attack might be to close a port, block a source IP, or rebuild a machine.
Incidents can be created:
Manually, by a security analyst monitoring incoming data or querying past data.
Automatically, as a result of a correlation rule being triggered. For more information, see
"Correlation Tab" section.
In the Incidents Tab, you can:
Manage Incident Views
Manage Incidents
Switch between existing Incident Views
NOTE: You need to have appropriate permissions to access this tab. Only an Administrator has
controls to enable/disable access to the features of Incidents for a user.

4.2 Introduction to User Interface

In the Incidents Tab, you will see the Display Incident View, Create Incident and Attachment
Viewer Configuration.
You can navigate to these functions from:
Table 4-1: Incident Tab -User Interface
Table 4-1
The Incident menu in the Menu Bar
4
Incidents Tab
93

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentinel 6.1 sp2

Table of Contents