Viewing Events That Triggered Correlated Events - Novell SENTINEL 6.1 SP2 - 02-2010 User Manual

Table of Contents

Advertisement

3 In the Create Incident dialog box, specify:
Title
State
Severity
Priority
Category
Responsible
Description
Resolution
4 Click Create. The incident is added under the Incidents tab of the Sentinel Control Center.
2.8 Viewing Events that Triggered Correlated
Events
Correlated events are determined based on the RT2 field value of the event. The RT2 field is set to
the name of the Correlation rule that triggered the Correlated event. This value is set only when the
event is generated by the Correlation engine. For the Correlated events, the Resource field is set to
Correlation
The SensorType field is set to T for the Correlated events that are routed to
If you are using the action
the Resource field to any value, the Resource field displays the value that you have set.
The View Trigger Events option is enabled only for Correlated events.
1 In the Real-Time event table of the Navigator or Snapshot, or an Event Query table, right-click
a Correlated event, and select View Trigger Events.
A window displays showing the events that triggered the rule and the name of the Correlation
Rule.
NOTE: For Correlated events, Trigger events are not available if events were routed to GUI
only. However, the View Trigger Events option is enabled even if the Trigger events are not
available.
46
Sentinel 6.1 User Guide
and the SensorType field is set to
Configure Correlated Event
. However, the following are the exceptions:
C
with a Correlation rule and you set
.
gui only

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentinel 6.1 sp2

Table of Contents