-
Votes
6
To support report for ISO 27002, year 2013.
Current version is ISO 27002, year 2005. When sentinel can support 2013?
Comments (1) | by: Fredric T. | over a year ago | Last activity over a year ago | Status changed over a year ago | Other
-
Votes
3
Data Synchronization enhancement
Enhance the data synchronization feature to allow the user to specify a start and finish date. Additionally, allow the user to kick-off the job on a specific date/time ...
Comments (2) | by: Richard B. | over a year ago | Last activity over a year ago | Status changed over a year ago | Other
-
Planned
4
notification on alert creation or owner change
there should be an option to notify the owner if an alert is assigned.
Comments (4) | by: Norbert K. | over a year ago | Last activity over a year ago | Status changed over a year ago | Other
-
Votes
6
Support Wildcarding In Dynamic Lists
Dynamic Filters should allow the same CIDR notation and wildcarding that Lucene allows specifically for IP addresses. Should also allow ranges like 10.14.1.[1-50]
Comments (1) | by: John G. | over a year ago | Last activity over a year ago | Status changed over a year ago | Other
-
Votes
1
General users should be able to view Health Status Info
General users should be able to view but not edit or modify the following collection - Overview & Event sources Storage - Health, report jobs, search jobs When ...
Comments (1) | by: Gus M. | over a year ago | Last activity over a year ago | Status changed over a year ago | Other
-
Votes
2
Supporting Syslog TCP with Octet Counting Framing
This framing mode is yet to have a wide acceptance. Also, the latest rsyslog does have an optional mode for this --> ...
Comments (0) | by: Pradeep K. | over a year ago | Last activity over a year ago | Status changed over a year ago | Other
-
Votes
6
Checksum for eventdata
Currently Sentinel creates checksum only for rawdata in secondary storage. There are some cases where checksum is needed to event data as well. -Br, TimoS
Comments (5) | by: Timo S. | over a year ago | Last activity over a year ago | Status changed over a year ago | Other
-
Votes
1
file connector
In Event Source Management, when processing a file with the file connector, once processing begins under connection information, it states "Reading file..." this is good ...
Comments (0) | by: Johnnie S. | over a year ago | Last activity over a year ago | Status changed over a year ago | Other
-
Votes
2
Request for incremental backup options in the backup script for ...
Provide the backup script the ability to create an differential (incremental) update of the backup since time the last backup was performed. This reduces the time and ...
Comments (0) | by: Brandon L. | over a year ago | Last activity over a year ago | Status changed over a year ago | Other
-
Votes
1
Provide end user with alertable event when Agent Manager Central ...
Ideally, we want the server to send a last message to the back-end when the Central Computer shuts down, but alternatively maybe there needs to be a 'are you alive' check ...
Comments (0) | by: Brandon L. | over a year ago | Last activity over a year ago | Status changed over a year ago | Other
-
Votes
2
Detect anomaly's in user logon activity
The ability to detect anomaly's in user logon activity, ie logging on to a system they have never used before.
Comments (1) | by: John G. | over a year ago | Last activity over a year ago | Status changed over a year ago | Other
-
Votes
3
Distributed search for All Identity Tracking Reports
All Identity Tracking Reports (Account Tracking, Recent Activity, Password changes, Suspicious activity overview ) have hardcoded Database in the selection of data source ...
Comments (1) | by: Khris F. | over a year ago | Last activity over a year ago | Status changed over a year ago | Other
-
Votes
5
Agent Manager Agent shoud send Heartbeat Events to detekt that it is ...
There should be a possiblity to detect that an Agent Manager Agent is running independent from sending events to Sentinel. I think one possibilty would be to have a ...
Comments (1) | by: Ulrich S. | over a year ago | Last activity over a year ago | Status changed over a year ago | Other
-
Votes
1
Customer needs Microsoft Radius data to be parsed correctly.
A customer has Microsoft Radius server and they need to be able to search on the mac address. Unfortunately all other systems use a format like this: 00:AA:00:12:34:56, ...
Comments (0) | by: Henk T. | over a year ago | Last activity over a year ago | Status changed over a year ago | Other
-
Votes
6
Ability to recreate an empty database (Postgres, mongo)
Normally running the 'backup_util.sh' is the part of the daily routine to make a backup about the required components (mainly the config, SI, alerts, etc...) In a case ...
Comments (0) | by: Erno P. | over a year ago | Last activity over a year ago | Status changed over a year ago | Other
-
Votes
3
Improve NoDataAlert
Is there a way to improve this event? Currently it gets logged as a generic 'Internal' event and all of the data is in the message field with none of it parsed out. ...
Comments (0) | by: Paul R. | over a year ago | Last activity over a year ago | Status changed over a year ago | Other
-
Votes
1
Event Export Filters
When exporting the Events from a Search query, there is only "Select All"/"Clear All". More often than not, a user would export the same fields for queries they run ...
Comments (0) | by: Ben W. | over a year ago | Last activity over a year ago | Status changed over a year ago | Other
-
Votes
2
Extend windows event logs possibilities in SAM
It could be interesting to extend windows logs (currently limited to secuity ad system logs) to others services/software like sysmon logs; powershell logs, RDP logs in ...
Comments (0) | by: david a. | over a year ago | Last activity over a year ago | Status changed over a year ago | Other
-
Votes
4
Export configuration in clear text
Customer HELAB need a tool to export the complete configuration in clear text or pdf to have a documentation of their system. This is needed because of regulation ...
Comments (0) | by: Ulrich S. | over a year ago | Last activity over a year ago | Status changed over a year ago | Other
-
Votes
1
Solution Designer - Bulk Copy
Need a method to capture all custom content in single click. Currently have to copy one item at a time. Group by group. Very time consuming. Option A: Ctrl/Shift+Left ...
Comments (1) | by: Bryan W. | over a year ago | Last activity over a year ago | Status changed over a year ago | Other