Novell SENTINEL RAPID DEPLOYMENT 6.1 - 12-2009 User Manual page 33

Table of Contents

Advertisement

The event summaries are displayed.
Advanced Search
An advanced search can search for a value in a specific event field or fields. The advanced search
criteria are based on the short names for each event field and the search logic for the index. To view
the field names and descriptions, the short names that are used in advanced searches, and whether
the fields are visible in the basic and detailed event views, see
To search for a value in a specific field, use the short name of the field, a colon, and the value. For
example, to search for an authentication attempt to Sentinel RD by user2, use the following text in
the search field:
evt:authentication AND sun:user2
Other advanced searches might include:
pn:NMAS AND sev:5
sip:123.45.67.89 AND evt:"Set Password"
Advanced Search Example
Figure 1-5
Multiple advanced search criteria can be combined by using the following Boolean operators:
AND (must be capitalized)
OR (must be capitalized)
NOT (must be capitalized and cannot be used as the only search criterion)
+
-
Managing Sentinel 6.1 Rapid Deployment Through the Web Interface
Table 1-2 on page
37.
33

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentinel rapid deployment 6.1

Table of Contents