Deploying And Undeploying Correlation Rules - Novell SENTINEL RAPID DEPLOYMENT 6.1 - 12-2009 User Manual

Table of Contents

Advertisement

4.3.7 Deploying and Undeploying Correlation Rules

Correlation rules can be deployed or undeployed from the Correlation Engine Manager or the
Correlation Rule Manager. You can undeploy all rules or a single rule.
The rules can be associated with one or more actions. If no action is selected, a default correlated
event is generated with the following values:
Default Correlated Event Details
Table 4-2
Field Name
Severity
Event Name
Message
Resource
SubResource
Other types of actions can be configured in the Action Manager:
Configure a Correlated Event replaces the default correlated event settings
Add to Dynamic List adds an element to a dynamic list
Remove from Dynamic List removes an element from a dynamic list
Execute a Command executes a shell or batch script
Execute a Script executes a script; only available for actions created in Sentinel 6.0
Send an Email by using default Sentinel mail settings
Create an Incident creates a Sentinel incident
Configure any Action from the Action Manager that was created from an Action plug-in that
takes a correlated event as input. For more information on the Action Manager, see
"Action Manager and Integrator," on page
To deploy correlation rules in the Correlation Engine Manager:
1 Open the Correlation Engine Manager window.
2 Right-click the engine you want to deploy the rule on and select Deploy Rule.
3 In the Rules tab, select the rule or rules you want to deploy.
4 In the Actions tab, select the action or actions you want to associate with the rule.
5 Click Deploy. Rules are deployed in an enabled state.
To deploy correlation rules in the Correlation Rule Manager:
1 Open the Correlation Rule Manager window.
2 Select a rule and click the Deploy rules link. The Deploy Rule window displays.
3 In the Deploy Rule window, select the engine to deploy the rule from the drop-down list.
4 (Optional) Select an action or add a new action.
Default Values
4
Same as the event name for the trigger event
Same as the message for the trigger event
Correlation
<Rule Name>
341.
Chapter 15,
Correlation Tab
95

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentinel rapid deployment 6.1

Table of Contents