Application Integration; Time; A.3.4 Application Integration; A.3.5 Time - Novell SENTINEL 6.1 SP2 - 02-2010 User Manual

Table of Contents

Advertisement

A.3.4 Application Integration

External application integration through standard APIs is central to Sentinel. For example, when
dealing with a third party trouble-ticketing system, Sentinel 6 can open an initial ticket in its own
iTRAC workflow remediation system. Sentinel then uses bi-directional API to communicate with
®
the other trouble ticketing systems—for example, Remedy
allowing straightforward integration
with external systems.
The API is Web Services-based and therefore allows any external systems that are SOAP-aware to
take advantage of pervasive integration with the Sentinel system.

A.3.5 Time

The time of an event is very critical to its processing. It is important for reporting and auditing
purposes as well as for real time processing. The correlation engine processes time-ordered streams
of events and detects patterns within events as well as temporal patterns in the stream. However, the
device generating the event might not know the real time when the event is generated. In order to
accommodate this, Sentinel allows two options in processing alerts from security devices: trust the
time the device reports and use that as the time of the event, or do not trust the device time and
instead stamp the event at the time it is first processed by Sentinel (by the Collector).
Sentinel is a distributed system and is made up of several processes that can be in different parts of
the network. In addition, there can be some delay introduced by the device. In order to accommodate
this, the Sentinel processes reorder the events into a time-ordered stream before processing.
The following illustration explains the concept of Sentinel Time.
448 Sentinel 6.1 User Guide

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentinel 6.1 sp2

Table of Contents