A Sentinel Architecture; Sentinel Features; Functional Architecture; A.1 Sentinel Features - Novell SENTINEL 6.1 SP2 - 02-2010 User Manual

Table of Contents

Advertisement

Sentinel Architecture
A
Sentinel is a security information and event management (SIEM) solution that automates the
collection, analysis and reporting of system network, application and security logs to help
organizations manage IT risk.
This section discusses the functional and technical architecture of Sentinel.
Section A.1, "Sentinel Features," on page 441
Section A.2, "Functional Architecture," on page 441
Section A.3, "Architecture Overview," on page 442
Section A.4, "Logical Architecture," on page 452

A.1 Sentinel Features

Sentinel allows you to monitor and manage a variety of functions. Some of the main functions
include:
Real-time views of large streams of events
Reporting capabilities based on real-time and historical events
Managing users and what they are able to see and do by permission assignment
Managing access to events for different users
Organizing events into incidents for efficient response management and tracking
Detecting patterns in events and streams of events
An intuitive and flexible rule-based language for correlation
Rules compiled for high performance
Scalable, multi-threaded, distributable, and extensible architecture
Sentinel processes communicate with each other through a message-oriented middleware (MOM).

A.2 Functional Architecture

Sentinel is composed of the following component subsystems, which form the core of the functional
architecture:
Section A.3.1, "iSCALE Platform," on page
Section A.3.3, "Event Source Management," on page
manage and monitor connections between Sentinel and third-party event sources, using
Sentinel Connectors and Sentinel Collectors.
In addition to ESM, there are a number of subcomponents that are hosted by a distributable
service called the Collector Manager. This service can be installed on a number of systems to
balance the processing load or for scalability. The data collection components are downloaded
from the Novell Content Web page and are installed to the Collector Managers via a central
ESM interface.
Section A.3.4, "Application Integration," on page
442: An event-driven scalable framework.
447: An extensible framework built to
448: An extensible application framework.
A
Sentinel Architecture
441

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentinel 6.1 sp2

Table of Contents