Viewing Events That Trigger Correlated Events - Novell SENTINEL RAPID DEPLOYMENT 6.1 - 12-2009 User Manual

Table of Contents

Advertisement

Vulnerability: Show related asset vulnerabilities
Advisor: Asset attack and alert information
iTRAC: Under this tab, you can assign a WorkFlow (iTRAC
History: Incident history
Attachments: You can attach any document or text file with pertinent information to this
incident
Notes: You can specify any general notes regarding this incident.
3 In the Create Incident dialog box, specify:
Title
State
Severity
Priority
Category
Responsible
Description
Resolution
4 Click Create. The incident is added under the Incidents tab of the Sentinel Control Center.
3.8 Viewing Events That Trigger Correlated
Events
You must right-click a correlated event in order to view the events that triggered the correlated
event. In the event table from which you are selecting the event, look in the summary display panel
on the right for an event that has a property of SensorType with a Value of C (C: correlated event).
To view events that triggered a correlated event:
1 In a Real Time Event Table of the Navigator or Snapshot, or in an event query table, right-click
a correlated event and select View Trigger Events.
A window opens, showing the events that triggered the rule and the name of the correlation
rule.
64
Sentinel 6.1 Rapid Deployment User Guide
)
TM

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentinel rapid deployment 6.1

Table of Contents