4.2 Understanding Data Collection Rules

Sentinel uses the Data collection rules created in Agent Manager to collect and monitor events. Agent Manager allows you to group data collection rules by storing them in data collection policies. Using the Sentinel Web console, you associate data collection policies with the device groups you want to monitor.

To associate data collection rules with device groups, start the Sentinel Web console, click Collection on the top menu, and then select Devices. For more information about associating data collection rules and policies to device groups, see the NetIQ Sentinel User Guide.

When you review a defined rule, Agent Manager displays the rule Properties window. For more information about displaying the Properties for a rule, see Working with Data Collection Rules. The Properties tabs typically display the rule criteria that you supply when creating data collection rules. For more information about any entry on a tab, see the Help.

Depending on the data collection rule, the following tabs may be available:

General

Specifies a name and whether the data collection rule is enabled. This tab also provides information about the data collection rule description, path, GUID, and last modified date.

Data Provider

Specifies the event or performance data provider name and type. For more information about data providers, see Understanding Data Providers.

Knowledge Base

Specifies information about the data collection rule, such as what caused an alert, how to resolve an issue, or how to configure the data collection rule or parameters in a script response.