Correlation rules can be deployed or undeployed from the Correlation Engine Manager or the Correlation Rule Manager. You can undeploy all rules or a single rule.
The rules can be associated with one or more actions. If no action is selected, a default correlated event is generated with the following values:
Table 2 Default Correlated Event Details
Field Name |
Default Values |
---|---|
|
4 |
|
Same as the event name for the trigger event |
|
Same as the message for the trigger event |
|
Correlation |
|
<Rule Name> |
Other types of actions can be configured in the Action Manager:
Configure a Correlated Event replaces the default correlated event settings
Add to Dynamic List adds an element to a dynamic list
Remove from Dynamic List removes an element from a dynamic list
Execute a Command executes a shell or batch script
Execute a Script executes a script; only available for actions created in Sentinel 6.0
Send an Email by using default Sentinel mail settings
Create an Incident creates a Sentinel incident
Configure any Action from the Action Manager that was created from an Action plug-in that takes a correlated event as input. For more information on the Action Manager, see Action Manager and Integrator.
To deploy correlation rules in the Correlation Engine Manager:
Open the Correlation Engine Manager window.
Right-click the engine you want to deploy the rule on and select
.In the
tab, select the rule or rules you want to deploy.In the
tab, select the action or actions you want to associate with the rule.Click
. Rules are deployed in an enabled state.To deploy correlation rules in the Correlation Rule Manager:
Open the Correlation Rule Manager window.
Select a rule and click the
link. The Deploy Rule window displays.In the Deploy Rule window, select the engine to deploy the rule from the drop-down list.
(Optional) Select an action or add a new action.
If nothing is selected, a Correlated event with default values is created.
Click
.To undeploy a single rule:
In the Correlation Engine Manager, right-click the rule and select
.or
In the Correlation Rule Manager, select the rule and click the
link.To undeploy all correlation rules:
Open the Correlation Engine Manager window.
Right-click the Correlation engine and select
.For trademark and copyright information, see Legal Notices.