Action Manager And Integrator; Action Manager - Novell SENTINEL RAPID DEPLOYMENT 6.1 - 12-2009 User Manual

Table of Contents

Advertisement

Action Manager and Integrator

1 5
Actions are used to execute some type of action in Sentinel, either manually or automatically. An
action plug-in framework was introduced in Sentinel
different ways of executing actions in Sentinel 6.0. The same Action framework is now used to
execute actions in all of the following contexts:
When a deployed correlation rule fires (automatic)
When a user chooses the action from within an incident
When a user chooses a right-click menu option using an action in an Active View
event table
The plug-in framework has several advantages over the method for using JavaScript actions in
previous versions of Sentinel.
There is no need to place the JavaScript file in a particular directory. The plug-in is placed in a
central repository.
There is no need to manually distribute the file to multiple machines in a distributed
environment. The plug-ins are downloaded as needed.
Importing the updated plug-in from one Sentinel Control Center machine is sufficient to update
the plug-in everywhere it is used.
One or more configured action instances can be created from an action plug-in by using different
parameters.
An action can be executed on its own, or it can make use of an Integrator instance, configured from
an Integrator plug-in. Integrators provide the ability to connect to an external system, such as an
LDAP, SMTP, or SOAP server, to execute an action.
Section 15.1, "Action Manager," on page 341
Section 15.2, "Action Plug-Ins," on page 343
Section 15.3, "Actions," on page 354
Section 15.4, "Integrator Manager," on page 360
Section 15.5, "Integrator Plug-Ins," on page 362
Section 15.6, "Integrators," on page 363

15.1 Action Manager

The Action Manager allows you to configure repeatable actions that can be executed in various
contexts throughout the Sentinel system. The Action Manager allows you to configure the following
types of actions:
Configure a Correlated Event
Add to Dynamic List
Remove from Dynamic List
Execute a Command
6.1. This framework consolidates several
TM
Action Manager and Integrator
15
or other
TM
341

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentinel rapid deployment 6.1

Table of Contents