Correlation Rules and Actions

Correlation rules are deployed to a specific correlation engine. During the control installation, Figure 1 shows the correlation engines in the target Sentinel system and the rules that are already running on those engines. Based on the number and complexity of the rules running on the engines, you can decide which correlation engine to deploy the correlation rule to.

Correlation rules deploy in an Enabled or Disabled state, depending on their status in the source Sentinel system when the Solution Pack was created.

If an Execute Script Correlation action (created in Sentinel 6.0) is associated with the correlation rule, the Solution Manager attempts to install the associated JavaScript code on all correlation engines. If any of the correlation engines is unavailable, a message displays.

You can cancel the control’s installation and fix the problem or continue installation on only the available correlation engines.

Figure 4 Unavailable Correlation Engines

The Execute Script Correlation action (created in Sentinel 6.0) cannot run on a particular correlation engine if the installation of the JavaScript code fails for that correlation engine. The .js file can be manually copied to the proper directory on the correlation engine. In a default installation, the proper directory is<install_directory>/config/exec.

If an Execute Command correlation action is associated with the correlation rule, the Solution Manager installs the command and its arguments, but the script, batch file, or utility must be manually configured on the correlation engines. This might require installing the utility, configuring permissions, or manually copying a script or batch file to the proper directory on the correlation engines.

In a default installation, the proper directory for the script file is <install_directory>/config/exec.

If a JavaScript Action is associated with the correlation rule, the Solution Manager installs the Action configuration, the Action plug-in, and the associated Integrator configuration and Integrator plug-in if needed.

For trademark and copyright information, see Legal Notices.