A Sentinel 6.1 Rapid Deployment Architecture; Sentinel 6.1 Rapid Deployment Features; Functional Architecture; A.2 Functional Architecture - Novell SENTINEL RAPID DEPLOYMENT 6.1 - 12-2009 User Manual

Table of Contents

Advertisement

Sentinel 6.1 Rapid Deployment
A
Architecture
Sentinel
6.1 Rapid Deployment (RD) is a simplified version and an alternate platform for Novell
TM
Sentinel that provides security information and an event management (SIEM) solution that
automates the collection, analysis, and reporting of system network, application, and security logs to
help organizations manage IT risks.
Sentinel 6.1 Rapid Deployment provides full Sentinel functionality in a single-box SUSE
package. It features an easy-to-install SIEM solution that uses open source components such as
PostgreSQL, ActiveMQ*, and JasperReports for the database, messaging, and reporting.
This section discusses the functional and technical architecture of Sentinel.
Section A.1, "Sentinel 6.1 Rapid Deployment Features," on page 385
Section A.2, "Functional Architecture," on page 385
Section A.3, "Architecture Overview," on page 387
Section A.4, "Logical Architecture," on page 398
A.1 Sentinel 6.1 Rapid Deployment Features
Sentinel allows you to monitor and manage a variety of functions. Some of the main functions
include:
Real-time views of large streams of events
Reporting capabilities based on real-time and historical events, through the Web interface
Managing users and what they are able to see and do by permission assignment
Managing access to events for different users
Organizing events into incidents for efficient response management and tracking
Detecting patterns in events and streams of events
An intuitive and flexible rule-based language for correlation
Rules compiled for high performance
Embedded Sentinel database, based on the open source PostgreSQL database engine
Web-based search tool to quickly search for strings and patterns within the Sentinel event
database
Web-based client application launch and installation
Sentinel processes communicate with each other through message-oriented middleware (MOM).

A.2 Functional Architecture

Sentinel 6.1 Rapid Deployment is composed of the following component subsystems, which form
the core of the functional architecture:
Sentinel 6.1 Rapid Deployment Architecture
A
®
®
Linux
385

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentinel rapid deployment 6.1

Table of Contents