Create Incident - Novell SENTINEL 6.1 SP2 - 02-2010 User Manual

Table of Contents

Advertisement

Command actions can be created to perform a non-interactive action, such as modifying a firewall
policy, entering a record in a database, or deactivating a user account. For an action that generates
output, such as a command to run a vulnerability scan, the command should refer to a script that runs
the command and then writes the output to a file.
NOTE: By default, the action output is stored to the working directory, $ESEC_HOME/data. The
action output can be written to a different directory by specifying a different storage location of the
output file in the script

3.6.5 Create Incident

Configure Action- Create Incident
Figure 3-6
NOTE: This type of action can only be used in Correlation deployments
This action type create an incident whenever a correlated event fires. You can also initiate an iTRAC
workflow process for remediation of that incident. For more information about the values of the
following parameters, see
Responsible
Title
Category
Severity
Priority
State
[Optional] iTRAC Process: dropdown of configured iTRAC processes
[Optional] Action Plugin to Execute: dropdown of configured JavaScript Actions
Chapter 4, "Incidents Tab," on page
93.
Correlation Tab
91

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentinel 6.1 sp2

Table of Contents