Configuring Rules; Filter Criteria; Adding A Rule - Novell SENTINEL LOG MANAGER 1.0.0.5 - ADMINISTRATION GUIDE 03-31-2010 Administration Manual

Hide thumbs Also See for SENTINEL LOG MANAGER 1.0.0.5 - ADMINISTRATION GUIDE 03-31-2010:
Table of Contents

Advertisement

Configuring Rules

7
You can configure rules to evaluate and filter all incoming events and deliver selected events to
designated output channels. For example, each severity 5 event can be e-mailed to a security analyst
distribution list or to an administrator.
This section describes the event channels and rules that can be used to send events from Novell
Sentinel
Log Manager to another system.
TM
Section 7.1, "Configuring Rules," on page 111
Section 7.2, "Configuring Actions," on page 114
Section 7.3, "Configuring E-Mail Notification of Auto-Created Event Sources without a Time
Zone," on page 125
Section 7.4, "Forwarding the Events to Another Sentinel System," on page 127
7.1 Configuring Rules
Sentinel Log Manager rules can be configured to filter events based on one or more of the
searchable fields. Each rule can be associated with one or more of the configured actions.
The rules are evaluated on a first-match basis in top-down order and the first matched rule is applied
to the events that matches the filter criteria.
Section 7.1.1, "Filter Criteria," on page 111
Section 7.1.2, "Adding a Rule," on page 111
Section 7.1.3, "Editing a Rule," on page 112
Section 7.1.4, "Ordering Rules," on page 112
Section 7.1.5, "Deleting a Rule," on page 113
Section 7.1.6, "Activating or Deactivating a Rule," on page 113

7.1.1 Filter Criteria

Rules can be based on any searchable event field. The available operators depend on the data type of
the event field. For example, match subnet is available for IP addresses, and match regex is available
for text fields.

7.1.2 Adding a Rule

You can add a filter-based rule and then define one or more channels where you want to output the
events that meet the rule criteria.
1 Log in to the Sentinel Log Manager as an administrator.
2 Click rules in the upper left corner of the page.
The Rules tab is displayed on the right pane of the page.
3 Click Add Rule.
7
®
Configuring Rules
111

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentinel log manager 1.0.0.5

Table of Contents