Aegis Adapter for Sentinel

Configuration Guide

This document describes how to install and configure the Aegis Adapter for Sentinel.

1.0 Legal Notice

For information about legal notices, trademarks, disclaimers, warranties, export and other use restrictions, U.S. Government rights, patent policy, and FIPS compliance, see https://www.netiq.com/company/legal/.

© 2016 NetIQ Corporation. All Rights Reserved.

2.0 Overview

The Aegis Adapter for Sentinel (Sentinel adapter) allows Aegis to communicate with Sentinel to:

The Sentinel adapter also includes Aegis workflow activities specific to Sentinel that Process Authors can use in the Workflow Designer.

For more information about activities or activity libraries, see the Process Authoring Guide for Aegis.

3.0 Sentinel Adapter Requirements

The Sentinel adapter requires the following software versions.

Component

Version

Sentinel

Version 7.4.0.0 or later. Install on a computer with network access to the computer where you want to install the Sentinel adapter.

Ensure you install the latest hotfixes and patches for the version you are using in your environment.

Aegis

One of the following versions installed on a computer with network access to the Sentinel adapter and the NetIQ Resource Management Namespace Provider:

  • 3.0, with the following hotfixes installed:

    • 7015363

    • 7015389

  • 3.1, with the following hotfixes installed:

    • 7015364

    • 7015709

  • 3.2, with the following hotfixes installed:

    • 7015365

    • 7015648

4.0 Ports

The Sentinel adapter uses port 8443 on the Sentinel server computer to communicate with Aegis.

5.0 Installation Overview

The following table provides an overview of tasks to install and configure the Sentinel adapter.

 

Steps

For more information, see…

  1. Configure the minimum rights and privileges for the Run As account.

Ensuring Minimum Rights and Privileges

  1. Install the Sentinel adapter.

Installing the Sentinel Adapter

  1. Configure the adapter to connect to additional Sentinel servers.

Configuring a Sentinel Server

  1. Verify the installation was successful.

Verifying a Successful Installation with Aegis

6.0 Ensuring Minimum Rights and Privileges

When you install the Sentinel adapter, you must specify an account that has a minimum of Manage All Alerts privileges in Sentinel. The logon account allows the Sentinel adapter to communicate with the specified Sentinel server.

7.0 Installing the Sentinel Adapter

You must install the Sentinel adapter on an Aegis Server computer. You cannot install the adapter remotely.

  1. Log on to the Aegis Server computer with a local administrator account.

  2. (Conditional) To install the adapter on a cluster, log on to the active node.

  3. Run the Aegis Adapter for Sentinel setup program (AegisAdapterforSentinel.exe) located in the Sentinel installation kit in the Installer folder under the subfolder appropriate for your locale.

  4. Follow the instructions in the wizard, and then click Finish.

  5. (Conditional) To install the adapter on a cluster, repeat this procedure on each passive node in the cluster.

8.0 Configuring a Sentinel Server

When the installation is complete, you can configure additional Sentinel servers with the Aegis Adapter Configuration Utility.

  1. Log on to the Aegis Server computer with a local administrator account.

  2. In the NetIQ program group, click NetIQ > Aegis > Aegis Adapter Configuration Utility.

  3. In the left pane, expand Sentinel Servers.

  4. On the Edit menu, click New Entry.

  5. Provide the appropriate information, and then click Validate Credentials.

  6. Save the Sentinel server information.

  7. Repeat Step 3 through Step 6 for each server you need to add.

  8. Close the Aegis Adapter Configuration Utility.

9.0 Verifying a Successful Installation with Aegis

The setup program for the Sentinel adapter installs a new event type that you can use to create triggers and triggering event definitions. To verify a successful installation, check the new event type in the Aegis Configuration Console.

  1. Start the Aegis Configuration Console.

    For more information about starting the Configuration Console, see the Administrator Guide for Aegis.

  2. In the Navigation pane, click Administration.

  3. In the left pane, click Triggering Event Definitions.

  4. In the Event Definitions View Tasks list, click Create New Event Definition.

  5. On the Create Triggering Event Definition window, click <event type>.

  6. Ensure Sentinel.Alert is in the list of available event types.

After verifying a successful installation, build a simple workflow with one of the activities in the Sentinel Activities library. For more information about building workflows, see the Process Authoring Guide for Aegis.

10.0 Aegis Workflow Activities Overview

The activities in the Sentinel Activities library allow Aegis to perform the following types of tasks, among others:

  • Retrieve the attributes for specific alerts

  • Retrieve the events related to a specific alert

  • Query the knowledge base and retrieve comments

  • Create, update, or close an alert

  • Add comments to an alert

  • Promote an alert to an incident

You can see all available activities by looking at the Sentinel Activities library in the Aegis Workflow Designer. For more information about each activity, see the Help.

11.0 Uninstalling the Sentinel Adapter

To uninstall the Sentinel adapter, use the Windows Add/Remove Programs tool.