Novell SENTINEL RAPID DEPLOYMENT 6.1 - 12-2009 User Manual page 291

Table of Contents

Advertisement

NOTE: You can cancel the execution of the cleanup script at any time by entering
prompt.
2 At the prompt, indicate which objects you want to remove from the database:
Which objects would you like to cleanup?
(1) Incidents
(2) Identities
(3) Both
3 At the prompts, enter the following information to connect to the PostgreSQL database:
Database server hostname (Press ENTER for default localhost)=>
Database name (Press ENTER for default SIEM) =>
Database username (press ENTER for default dbauser)
The database connection is verified before proceeding to the next step.
4 Conditional) If you selected to clean incidents:
The following prompt displays:
Would you like to backup Incidents first? (y or n) =>
4a If you select
to back up the incidents, enter the destination directory (a full path or a
y
path relative to the location of the cleanup script) for the backup files.
The user running the script must have permission to write to this directory.
4b Select an incident cleanup option:
Delete Incidents By Query: You are prompted to enter a custom SELECT query.
For example:
select inc_id from incidents where inc_id=500
The SELECT statement cannot include quotation marks.
Delete Incidents By Rule: You are prompted to enter the name of the Correlation
rules that created the incidents. For example:
My Test Rule
Delete Incidents By Id: You are prompted to enter the ID of a specific incident. For
example:
101
(q) Quit without action
4c At the Incident Cleanup Confirmation prompt, enter
enter
to quit without performing any cleanup.
abort
The results of the incident cleanup are written to the specified log file.
You should review the log file for any errors before continuing.
5 Conditional) If you selected to clean identity:
5a At the Identity Cleanup Confirmation prompt, enter
enter
to quit without performing the identity cleanup.
abort
The results of the Identity Cleanup are written to the specified log file.
You should review the log file for any errors before continuing.
5b In addition to deleting the Identity information from the database tables, the script
attempts to delete the Identity Account Map file (
to start the incident cleanup or
start
to start the Identity cleanup or
start
identityAccountMap.csv
at any
q
).
Utilities 291

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentinel rapid deployment 6.1

Table of Contents