Novell SENTINEL 6.1 SP2 manuals
SENTINEL 6.1 SP2
Table of contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Preface
- Introduction
- Sentinel User Interfaces
- Sentinel Data Manager
- Sentinel Communication Server
- Sentinel Plugins
- Reports
- System Requirements
- Database Supported Platforms
- Sentinel Component Supported Platforms
- Platform Support Exceptions and Cautions
- Hardware Recommendations
- Supported Hardware
- Production Configuration
- High-Performance Production Configuration
- Virtual Environments
- Installing Sentinel 6.1 SP2
- Sentinel Configurations
- Solaris
- Port Numbers Used for Sentinel 6.1
- Providing Power User Privileges to Domain Users
- Authentication Mode Settings on Microsoft SQL
- Sentinel Server Installation Prerequisites
- Creating Group and User Accounts for Oracle (Solaris Only)
- Installing Oracle
- Custom Installation
- Starting the Installation
- Configuring the Database on Windows
- Configuring the Database on Linux or Solaris
- Completing the Installation
- Console Installation on Linux or Solaris
- Installing Sentinel as a Domain user
- Configuring the SMTP Integrator to Send Sentinel Notifications
- Collector Service
- Managing Time
- High-Performance Configuration
- LDAP Authentication
- Configuring Multiple LDAP Servers for Failover
- Migrating LDAP User Accounts from Sentinel 6.1 SP1 Hotfix 2 to Sentinel 6.1 SP2
- Updating the License Key
- Testing the Installation
- Clean Up from Testing
- Getting Started
- Adding Sentinel Components
- Multiple DAS_Binary Processes
- Communication Layer (iSCALE)
- SSL Proxy and Direct Communication
- Collector Manager
- Changing the Communication Encryption Key
- Increasing AES Key Strength
- Crystal Reports for Windows
- Configuration Requirements
- Installation Overview
- Installation Overview of Crystal Reports Server with SQL Server 2005
- Installation Overview of Crystal Reports Server with Oracle
- Installing Microsoft Internet Information Server (IIS) and ASP.NET
- Authentication
- Installing Crystal Reports Server for Oracle
- Downloading the Service Packs for Crystal Reports
- Patching Crystal Reports
- Publishing Crystal Report Templates
- Using the Solution Manager to Publish Report Templates
- Using the Central Management Console to Publish Report Templates
- Setting a Named User Account
- Disabling the Sentinel Top 10 Reports
- Configuring the Sentinel Control Center to Integrate with Crystal Reports Server
- High-Performance Configurations for Crystal
- Using the Aggregration Service for Reports
- Report Development
- Crystal Reports for Linux
- Overview
- Installing Crystal Reports Server XIR2
- Publishing Crystal Reports Templates
- Publishing Report Templates using Solution Manager
- Publishing Report Templates – Crystal Publishing Wizard
- Publishing Report Templates – Central Management Console
- Using the Crystal XI R2 Web Server
- Configuring Reports Permissions
- Configuring Sentinel Control Center to Integrate with Crystal Reports Server
- Utilities and Troubleshooting
- Reports Using Aggregation Service
- Using Crystal Reports
- Uninstalling Sentinel
- Uninstall for Windows
- Sentinel Settings
- B.1 Installing Oracle 11g
- B.1.2 Oracle 11g Installation on SLES 10
- B.1.3 Oracle 11g Installation on Red Hat Linux 4
- B.1.4 Oracle 11g Installation on Solaris 10
- B.2 Upgrading the Database from Oracle 10g to Oracle 11g
- B.3 Installing Oracle 10g
- B.3.2 Oracle 10g Installation on Red Hat Linux 4
- B.3.3 Oracle 10g Installation on Solaris 10
- C.1 Configuring the Oracle RAC Database
- C.1.2 Creating the Sentinel Tablespaces
- C.1.3 Creating the Sentinel Database User
- C.3 Configuring the Connection Properties File
- C.4 Configuring the Connection for Sentinel Data Manager
- Chapter 8, "Crystal Reports for Linux," on
SENTINEL 6.1 SP2
Table of contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Preface
- Sentinel TM User Reference Introduction
- Sentinel Event Fields
- Free-Form Filters and Correlation Rules
- Actions
- Proprietary Collectors
- Sentinel Control Center User Permissions
- General
- General – Integration Actions
- iTRAC
- Integrators
- Event Source Management
- Administration
- Correlation
- Sentinel Correlation Engine RuleLG Language
- Event Operations
- Window Operation
- Trigger Operation
- Rule Operations
- Sequence Operation
- Union Operator
- Differences between Correlation in 5.x and 6.x
- Sentinel Data Access Service
- DAS Logging Properties Configuration Files
- Certificate Management for DAS_Proxy
- Sentinel Accounts and Password Changes
- Changing Password
- Sentinel Updates After a Password Change
- Sentinel Database Views for Oracle
- ACTVY_REF_RPT_V
- ADV_NXS_FEED_V
- ADV_NXS_PRODUCTS_V
- ADV_NXS_SIGNATURES_V
- ADV_OSVDB_DETAILS_V
- ADV_NXS_KB_PATCH_V
- ADV_NXS_KB_PRODUCTSREF_V
- ASSET_HOSTNAME_RPT_V
- ASSET_RPT_V
- ASSET_X_ENTITY_X_ROLE_RPT_V
- ATTACHMENTS_RPT_V
- CONFIGS_RPT_V
- CORRELATED_EVENTS_RPT_V (legacy view)
- CUST_HIERARCHY_V
- ENV_IDENTITY_RPT_V
- ESEC_CONTENT_GRP_RPT_V
- ESEC_CTRL_CTGRY_RPT_V
- ESEC_DISPLAY_RPT_V
- ESEC_PORT_REFERENCE_RPT_V
- ESEC_SEQUENCE_RPT_V
- EVENTS_ALL_RPT_V1 (legacy view)
- EVENTS_RPT_V3
- EVT_AGENT_RPT_V
- EVT_AGENT_RPT_V3
- EVT_ASSET_RPT_V3
- EVT_DEST_EVT_NAME_SMRY_1_RPT_V
- EVT_DEST_TXNMY_SMRY_1_RPT_V
- EVT_PORT_SMRY_1_RPT_V
- EVT_PRTCL_RPT_V3
- EVT_SRC_COLLECTOR_RPT_V
- EVT_SRC_MGR_RPT_V
- EVT_SRC_SMRY_1_RPT_V
- EVT_SRC_SRVR_RPT_V
- EVT_XDAS_TXNMY_RPT_V
- HIST_CORRELATED_EVENTS_RPT_V (legacy view)
- INCIDENTS_EVENTS_RPT_V
- INCIDENTS_VULN_RPT_V
- MSSP_ASSOCIATIONS_V
- PERSON_RPT_V
- PRODUCT_RPT_V
- SENSITIVITY_RPT_V
- SENTINEL_RPT_V
- UNASSIGNED_INCIDENTS_RPT_V
- USR_ACCOUNT_RPT_V
- USR_IDENTITY_RPT_V
- VULN_CALC_SEVERITY_RPT_V
- VULN_INFO_RPT_V
- VULN_RSRC_RPT_V
- VULN_RSRC_SCAN_RPT_V
- VULN_SCANNER_RPT_V
- WORKFLOW_INFO_RPT_V
- Sentinel Database Views for Microsoft SQL Server
- ACTVY_RPT_V
- ADV_NXS_MAPPINGS_V
- ANNOTATIONS_RPT_V
- ASSET_CATEGORY_RPT_V
- ASSET_LOCATION_RPT_V
- ASSET_VALUE_RPT_V
- ASSOCIATIONS_RPT_V
- AUDIT_RECORD_RPT_V
- CONTACTS_RPT_V
- CRITICALITY_RPT_V
- CUST_RPT_V
- ESEC_CONTENT_GRP_CONTENT_RPT_V
- ESEC_CONTENT_PACK_RPT_V
- ESEC_CTRL_RPT_V
- ESEC_PROTOCOL_REFERENCE_RPT_V
- ESEC_UUID_UUID_ASSOC_RPT_V
- EVT_ASSET_RPT_V
- EVT_DEST_SMRY_1_RPT_V
- EVT_NAME_RPT_V
- EVT_PRTCL_RPT_V
- EVT_SEV_SMRY_1_RPT_V
- EVT_SRC_GRP_RPT_V
- EVT_SRC_RPT_V
- EVT_TXNMY_RPT_V
- EVT_USR_RPT_V
- EXTERNAL_DATA_RPT_V
- HIST_EVENTS
- HIST_EVENTS_RPT_V (legacy view)
- INCIDENTS_RPT_V
- L_STAT_RPT_V
- LOGS_RPT_V
- ORGANIZATION_RPT_V
- ROLE_RPT_V
- RPT_LABELS_RPT_V
- SENTINEL_PLUGIN_RPT_V
- USERS_RPT_V
- USR_IDENTITY_EXT_ATTR_RPT_V
- VULN_CODE_RPT_V
- VULN_RPT_V
- VULN_SCAN_RPT_V
- WORKFLOW_DEF_RPT_V
- Deprecated Views
- B.1 Sentinel Services
- B.2.1 Disadvantages of running a service in the context of a user logon
- B.3 To Setup NT AUTHORITY\NetworkService as the Logon Account for Sentinel Service
- B.3.2 Changing logon account
- B.3.3 Setting the Sentinel Service to Start Successfully
- C.1 Advisor
- C.2 Collector Manager
- C.3 Correlation Engine
- C.4 Data Access Server (DAS)
- C.5 Sentinel Communication Server
- C.6 Sentinel Service
- D.1 Sentinel Database Instance
- D.2.1 Summary
- D.2.4 esecdba
- D.3.3 ESEC_ETL
- D.3.4 ESEC_USER
- D.4 Sentinel Server Roles
- E Sentinel Log Locations
- E.3 Advisor
- E.7 Aggregation
- E.11 Sentinel Control Center
SENTINEL 6.1 SP2
Table of contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Sentinel Control Center
- Incidents
- Correlation
- Solution Packs
- Introduction to the User Interface
- Menu Bar
- Tabs
- Frames
- Saving User Preferences
- Configuring the Attachment Viewer
- Active Views Tab
- Reconfiguring Total Display Time
- To Reset Parameters and Chart Type of an Active View
- Rotating a 3D Bar or Ribbon Chart
- Creating Incidents
- Viewing Events that Triggered Correlated Events
- Investigating an Event or Events
- Investigate – Graph Mapper
- Historical Event Query
- Active Browser
- Viewing Advisor Data
- Viewing Asset Data
- Viewing Vulnerabilities
- Ticketing System Integration
- Using Custom Menu Options with Events
- Taking a Snapshot of a Navigator Window
- Sorting Columns in a Snapshot
- Correlation Tab
- Technical Implementation
- Correlation Rules
- Opening the Correlation Rule Manager
- Creating Correlation Rules
- Deploying/Undeploying Correlation Rules
- Enabling/Disabling Rules
- Renaming and Deleting a Correlation Rule
- Exporting a Correlation Rule
- Dynamic Lists
- Adding a Dynamic List
- Modifying a Dynamic List
- Correlation Engine
- Starting or Stopping Correlation Engine
- Configure Correlated Event
- Add to Dynamic List
- Remove from Dynamic List
- Execute a Command
- Create Incident
- Send Email
- Incidents Tab
- Incident View
- Manage Incident Views
- Modifying a View
- Deleting a View
- Viewing an Incident
- Executing Incident Actions
- Emailing an Incident
- Modifying Incidents
- Deleting Incidents
- iTRAC Workflows
- Template Manager
- Template Builder Interface
- Creating Templates
- Managing Templates
- Steps
- Decision Steps
- Activity Steps
- End Step
- Managing Steps
- Transitions
- Conditional Transitions
- Else Transitions
- Timeout Transitions
- Error Transition
- Activities
- Incident Command Activity
- Incident Composite Activity
- Managing Activities
- Process Management
- Display Status
- Changing Views in Process Manager
- Starting or Terminating a Process
- Work Items
- Processing a Work Item
- Manage Work Items Of Other Users
- Analysis Tab
- Top Ten Reports
- Running a Report from Crystal Reports Server
- Creating an Offline Query
- Advisor Usage and Maintenance
- Understanding Exploit Detection
- Generating the Exploit Detection File
- The Advisor Window
- Processing the Advisor Feed
- Configuring the Advisor Products for Exploit Detection
- Downloading the Advisor Feed
- Downloading the Advisor Feed Manually
- Viewing the Advisor Data
- Advisor Reports
- Resetting the Advisor Password
- Download Manager
- Creating a Download Configuration
- Editing a Download Configuration
- Downloading the Feed Instantly
- Event Source Management
- Plugin Repository
- Tool Bar
- Live View
- Graphical ESM View
- Tabular ESM View
- Components of Event Source Hierarchy
- Component Status Indicators
- Adding Components to Event Source Hierarchy
- Debugging
- Collector Workspace and Collector Directory
- Debugging JavaScript Collectors
- Generating a Flat File using the Raw Data Tap
- Export Configuration
- Import Configuration
- Reset Layout
- Redo Layout
- Administration
- Introduction to User Interface
- Crystal Report Configuration
- Servers View
- Monitoring a Process
- Creating a Servers View
- Filters
- Global Filters
- Configuring Public and Private Filters
- Color Filter Configuration
- Configure Menu Options
- Adding an Option to the Event Menu
- Cloning an Event Menu Option
- Modifying an Event Menu Option
- Rearranging Event Menu Options
- DAS Statistics
- Mapping
- Adding Map Definitions
- Adding a Number Range Map Definition
- Editing Map Definitions
- Deleting Map Definitions
- Updating Map Data
- Event Configuration
- Renaming Tags
- Report Data Configuration
- Oracle and Microsoft SQL 2005 Authentication
- Opening the User Manager Window
- Modifying a User Account
- Viewing Details of a User Account
- Adding an iTRAC Role
- Viewing Details of a Role
- Sentinel Data Manager
- Partitions Tab
- Tablespaces Tab
- Partition Configuration
- SDM Command Line
- Utilities
- Starting a Sentinel Server
- Operational Scripts
- Troubleshooting Scripts
- Version Information
- Sentinel .dll and .exe File Version Information
- Components
- Prerequisites
- Updating Your License Key
- Quick Start
- Exploit Detection
- Event Query
- iTRAC
- Report Analyst
- Administrators
- Components of a Solution Pack
- Permissions for Using Solution Packs
- Solution Manager
- Managing Solution Packs
- Opening Solution Packs
- Installing Content from Solution Packs
- Implementing Controls
- Testing Controls
- Uninstalling Controls
- Viewing Solution Pack Status
- Deleting Solution Packs
- Solution Designer
- Connection Modes
- Creating a Solution Pack
- Adding Content to a Solution Pack
- Documenting a Solution Pack
- Editing a Solution Pack
- Deploying an Edited Solution Pack
- Actions and Integrator
- Action Manager
- Action Plugins
- Importing JavaScript Files
- Actions
- Editing Actions
- Using JavaScript Actions
- Integrator Manager
- Permissions for Using Integrators
- Integrator Plugins
- Deleting Integrator Plugins
- Deleting an Integrator Instance
- Integrator Events Query
- Using Integrators from Actions
- Sentinel Link Solution
- Configuring Sentinel Link
- Setting Up a Sentinel Link Connection
- Configuring Sentinel Systems for Sending Events
- Configuring Sentinel or Sentinel Rapid Deployment System as a Sender
- Verifying a Sentinel Link
- Identity Integration
- Integration with Novell Identity Manager
- Identity Browser
- Searching Profiles
- Viewing Profile Details
- Reports
- A Sentinel Architecture
- A.3 Architecture Overview
- A.3.2 Sentinel Event
- A.3.3 Event Source Management
- A.3.4 Application Integration
- A.3.6 System Events
- A.3.7 Processes
- A.4 Logical Architecture
- A.4.1 Collection and Enrichment Layer
- A.4.2 Business Logic Layer
- A.4.3 Presentation Layer
- B.1 Advisor Audit Events
- B.2 Download Manager Audit Events
- B.2.3 Download Config Updated
- B.3.2 Creating Entry For External User
- B.3.5 Locked Account
- B.3.7 Too Many Active Users
- B.3.10 User Logged Out
- B.4.2 Create Role
- B.4.5 Delete Role
- B.4.8 Remove Users From Role
- B.4.11 Updating User
- B.5.3 Database Space Very Low
- B.5.6 Error Processing Event Message
- B.5.9 Event Insertion is resumed
- B.5.11 Event Processing Failed
- B.5.14 Partition Configuration
- B.6.1 Creating Summary
- B.6.4 Enabling Summary
- B.7.1 Error
- B.7.4 Error Refreshing Map
- B.7.7 Loaded Large Map
- B.7.10 Refreshing Map from Cache
- B.7.12 Save Data File
- B.7.15 Timeout Refreshing Map
- B.7.17 Update
- B.8.3 Event Router is Stopping
- B.9.1 Correlation Action Definition
- B.9.4 Correlation Engine is Stopped
- B.9.7 Deploy Rules With Actions To Engine
- B.9.10 Rename Correlation Engine
- B.9.13 Rule Deployment is Stopped
- B.9.16 UnDeploy All Rules From Engine
- B.10.1 Collector Manager Initialized
- B.10.4 Collector Manager Stopped
- B.10.7 Event Source Manager Callback
- B.10.10 No Data Alert
- B.10.13 Port Start
- B.10.16 Restart Plugin Deployments
- B.10.19 Start Event Source Group
- B.10.22 Stop Event Source Group
- B.11.1 Start Event Source
- B.12.2 Stop Collector
- B.13.3 Stop Event Source Server
- B.14.3 File Rotation
- B.14.5 Process Start Error
- B.15.1 Active View Created
- B.15.4 Active View Now Permanent
- B.16 Data Objects
- B.16.3 Viewing Configuration Store
- B.17.2 Deleting an Activity
- B.18.2 Adding Process Definition
- B.18.5 Creating User
- B.18.8 Deleting Process Definition
- B.18.11 Get Incident
- B.18.14 Saving Process Definition
- B.19.2 Controlled Process is started
- B.19.5 Importing Plugin
- B.19.8 Process Restarts
- B.19.11 Restarting Processes
- B.19.14 Stopping Process
- B.19.18 Watchdog Process is stopped
Related products
SENTINEL 6.1 SP2 - 02-2010SENTINEL 6.1.1.0 - READMESentinel Rapid Deployment 6.1SENTINEL 6.1 SP2 - INSTALLATION GUIDE 02-2010SENTINEL 6.1 SP1 HOTFIX 2 - READ ME 9-2009SENTINEL 6.1 SP1 HOTFIX 1 - READ ME 7-8-2009SENTINEL LOG MANAGER 1.0.0.4 - SSENTINEL LOG MANAGER 1.0.0.5 - SSENTINEL RAPID DEPLOYMENT 6.1 - 12-2009SENTINEL RAPID DEPLOYMENT 6.1 - 06-15-2009Novell categories
More Novell categoriesmanualsdatabase
Your AI-powered manual search engine