Collection And Enrichment Layer - Novell SENTINEL RAPID DEPLOYMENT 6.1 - 12-2009 User Manual

Table of Contents

Advertisement

Sentinel Logical Layers
Figure A-10
The collection and enrichment layer aggregates the events from external data sources,
transforms the device-specific formats into Sentinel format, enriches the native events source
with business-relevant data, and dispatches the event packets to the message bus. The key
component orchestrating this function is the Collector, aided by a taxonomy mapping and
global filter service.
The business logic layer contains a set of distributable components. The base component is a
Remoting service that adds messaging capabilities to the data objects and services to enable
transparent data access across the entire network and Data Access service that is an object
management service to allow users to define objects using metadata. Additional services
include Correlation, Query Manager, Workflow, Event Visualization, Incident Response,
Health, Advisor, Reporting, and Administration.
The presentation layer renders the application interface to the end user. A comprehensive
dashboard called the Sentinel Control Center offers an integrated user workbench consisting of
an array of seven different applications accessible through a single common framework. This
cross-platform framework is built on Java 1.4 standards and provides a unified view into
independent business logic components: real-time interactive graphs, actionable incident
response, automated enforceable incident workflow, reporting, incident remediation against
known exploits and more.
Each of the layers are illustrated in
following sections.
Section A.4.1, "Collection and Enrichment Layer," on page 399
Section A.4.2, "Business Logic Layer," on page 403
Section A.4.3, "Presentation Layer," on page 409
A.4.1 Collection and Enrichment Layer
Event Source Management (ESM) provides tools to manage and monitor connections between
Sentinel and third-party event sources. Events are aggregated by using a set of flexible and
configurable Collectors, which collect data from a myriad of sensors and other devices and sources.
User can use prebuilt Collectors, modify existing Collectors or build their own Collectors to ensure
that the system meets all requirements.
Figure A-10
and subsequently discussed in detail in the
Sentinel 6.1 Rapid Deployment Architecture 399

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentinel rapid deployment 6.1

Table of Contents