Novell SENTINEL RAPID DEPLOYMENT 6.1 - 12-2009 User Manual page 92

Table of Contents

Advertisement

Composite Rule
A composite rule is comprised of two or more subrules. A composite rule can be defined so that all
or a specified number of the subrules must fire within the defined time frame. Composite rules have
an optional group by field, which can be any populated field from the events.
NOTE: When a subrule is used to create a composite rule, a copy of the subrule is added to the
composite rule's definition. Because a copy is added, changes to the original subrule do not affect
the composite rule.
To create a composite rule:
1 Open the Correlation Rule Manager window and select a folder from the drop-down list to
which this rule is added.
2 Click the Add button located on the top left corner of the screen. The Correlation Rule window
displays. Select Composite Rule.
3 In the Composite Rule window, click Add Rule to select sub rules to create a composite rule.
The Add Rule window displays.
4 Select a rule or a set of rules nd click OK.
5 Set parameters for the rule to fire.
6 To group event tags according to the attributes, click Add/Edit. The Attribute window displays.
7 Select the attribute you want, then preview the rule in RuleLg preview box.
8 Click Next.The Update Criteria window displays.
9 Update criteria for the rule to fire and click Next.
10 Provide a name for this rule. You have an option to modify the rule folder.
92
Sentinel 6.1 Rapid Deployment User Guide

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentinel rapid deployment 6.1

Table of Contents