• Votes

    3

    File Connector should support an option to rename the processed logs

    Originally tracked in bug: https://bugzilla.netiq.com/show_bug.cgi?id=455690 The file connector should follow the pattern that IDM follows, which is simply provide the ...

  • Votes

    4

    Samba v2 and v3 support in file connector

    File connector should be able to use SMB v2 and v3.

  • Votes

    8

    Schedule download for scp or/and sshfs for file connector

    SCP option in the file connector should have schedule/recurring download option. sshfs together with CIFS and NFS, would be very useful option too.

  • Votes

    18

    View single raw data event in the WebUI

    Sometimes I miss the ability to quickly preview a single raw data (event) related to the event I want to check. Customers are asking for this too.

  • Votes

    9

    CM backup

    Customers are asking why we do not have official backup/restore script or other CLI method to export/import CM configuration.

  • Planned

    16

    Export PDF reports with password protection in Sentinel

    The possibility to export reports (CSV, PDF or other format) with password protection to increase security and sending by email.

  • Planned

    2

    Forwarding of netflow data

    The ability to forward raw netflow data using spoofed or non spoofed source address. Allowing additional tools to get flow data

  • Planned

    6

    Raw bulk syslog event forwarding

    Allow forwarding of raw syslog events at volume to additional locations with the ability to spoof the source ip on UDP sessions

  • Votes

    8

    Ability to import production collectors into the SDK to customize and ...

    Provide SDK versions of released collectors - all the data is already contained in the released collector. This step just removes the task of creating a new collector in ...

  • Votes

    3

    authorization for actions

    Allow actions to have access controls and be aware of the user running the action. I may have users in role 1 that I with to allow to disable switch ports through an ...

  • Votes

    3

    Customize the search result fields

    Search result display a set of attributes ie sn: sip: , this can be expanded upon by selecting the more option and you can view all the results by selecting the All ...

  • Planned

    4

    Support IPv6 through and through

    Instead of hacking the system, such as TID 7016555, to make any use of IPv6, Sentinel should not only accept IPv6 syntaxes, but store and parse them in such a way that ...

  • Planned

    8

    Support both IPv4 and IPv6 for IP2Location

    IP2Location offers IPv4 and IPv6 as separate databases (e.g. DB5 & DB5IPV6) so the feed should be capable of processes both CSV's into Map without the need for complex ...

  • Planned

    5

    Extend Feed Frequency Options

    At the moment the minimum Feed frequency is Weekly. Considering IP2Location only updates their databases once a month, this weekly minimum is a waste of resources to ...

  • Votes

    2

    Use Delta RPMs for Appliance

    The size of the current RPMs is very significant, both to download/bandwidth and the temporary disk requirements. This is extremely slow and often unreliable when ...

  • Votes

    17

    Customize Email-Alert fields

    Situation: in the js-email-alert function you can choose between "Important Data", "All-Data", and "Minimal Data". If you use CustomVariable or need some other variables ...

  • Planned

    14

    Run correlation rules on history data

    It would be nice to have the ability to run correlation rule againt history data and let the rule fire alerts. Now it is only possible to test the rule, but not to have ...

  • Votes

    5

    Permissions to Security Intelligence Boards

    Changing the permission structure: Now: Only access to all events for a user and permissions to SI boards are possible. If you limit the event view with a filter you ...

  • Votes

    2

    Manage alerts from multiple sentinel deployment using single ...

    In the client's environment, they have multiple Sentinel deployments (Prod, Test, DMZ etc) Each of the environments have their own alerts that they can investigate and ...

  • Votes

    3

    Distributed search for All Identity Tracking Reports

    All Identity Tracking Reports (Account Tracking, Recent Activity, Password changes, Suspicious activity overview ) have hardcoded Database in the selection of data source ...