Novell Sentinel Training Day 4
To conclude my thoughts on the training. I thought I would include some screenshots so you can see Sentinel in action for yourself!
To sum up, the way Sentinel works is:
- Logs are pulled into Sentinel and each line is seperated into events with severity levels ranging from 1 to 5
- You define filters to look for events of interest. For example a filter might look like:
filter(((e.DeviceCategory = “IDS”) and (e.Severity >= 4))) - Multiple Events can be groups together and marked as incidents. Each incident can be assigned a category and can be assigned to a person for further investigation
- Utilizing Filters a correlated event can kick of an action (or trigger) such as sending an e-mail, appending a list, appending an ldap attribute or kicking off a javascript file (for further flexibility)
- ProcessWork Flows can be designed to dictate the logic behind how an event is handled. The chain of command can be worked into the work flow. I.e. when a correlated event takes place ad Analyst can be prompted to check out the incident. Once the analyst attempts to rectify the problem and closes it out. It then can go to an Administrator who can further investigate or close out the incident.
This is the process in a nutshell, if you follow the screens after reading the explanation it might make more sense.











![Reblog this post [with Zemanta]](http://img.zemanta.com/reblog_e.png?x-id=07d971c4-eb62-4193-98cf-b0a495716637)

![Reblog this post [with Zemanta]](http://img.zemanta.com/reblog_e.png?x-id=a26b5b13-3176-481a-a263-e736fce86b09)