Incidents Tab; Understanding An Incident; Introduction To User Interface - Novell SENTINEL RAPID DEPLOYMENT 6.1 - 12-2009 User Manual

Table of Contents

Advertisement

Incidents Tab

5
In Sentinel
, a set of related events (for example, a possible attack) can be grouped together to form
TM
an incident. An incident in the Open state alerts you to investigate, resolve, and close the incident.
For example, the resolution to an attack might be to close a port, block a source IP, or rebuild a
machine.
Section 5.1, "Understanding an Incident," on page 109
Section 5.2, "Introduction to User Interface," on page 109
Section 5.3, "Manage Incident Views," on page 111
Section 5.4, "Manage Incidents," on page 115
Section 5.5, "Switch between Existing Incident Views," on page 121

5.1 Understanding an Incident

Incidents can be created:
Manually, by a security analyst monitoring incoming data or querying past data.
Automatically, as a result of a correlation rule being triggered. For more information, see
Chapter 4, "Correlation Tab," on page
In the Incidents tab, you can:
Manage incident views
Manage incidents
Switch between existing incident views
NOTE: You need to have appropriate permissions to access this tab. Only an Administrator has
controls to enable/disable access to the features of incidents for a user.

5.2 Introduction to User Interface

In the Incidents tab, you see the Display Incident View, Create Incident, and Attachment Viewer
Configuration.
You can navigate to these functions from different places:
Table 4-1: Incident Tab User Interface
Table 5-1
User Interface
83.
Description
The Incident menu in the menu bar
5
Incidents Tab
109

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentinel rapid deployment 6.1

Table of Contents