• Planned

    5

    Extend Feed Frequency Options

    At the moment the minimum Feed frequency is Weekly. Considering IP2Location only updates their databases once a month, this weekly minimum is a waste of resources to ...

  • Votes

    2

    Use Delta RPMs for Appliance

    The size of the current RPMs is very significant, both to download/bandwidth and the temporary disk requirements. This is extremely slow and often unreliable when ...

  • Votes

    17

    Customize Email-Alert fields

    Situation: in the js-email-alert function you can choose between "Important Data", "All-Data", and "Minimal Data". If you use CustomVariable or need some other variables ...

  • Planned

    14

    Run correlation rules on history data

    It would be nice to have the ability to run correlation rule againt history data and let the rule fire alerts. Now it is only possible to test the rule, but not to have ...

  • Votes

    5

    Permissions to Security Intelligence Boards

    Changing the permission structure: Now: Only access to all events for a user and permissions to SI boards are possible. If you limit the event view with a filter you ...

  • Votes

    2

    Manage alerts from multiple sentinel deployment using single ...

    In the client's environment, they have multiple Sentinel deployments (Prod, Test, DMZ etc) Each of the environments have their own alerts that they can investigate and ...

  • Votes

    3

    Distributed search for All Identity Tracking Reports

    All Identity Tracking Reports (Account Tracking, Recent Activity, Password changes, Suspicious activity overview ) have hardcoded Database in the selection of data source ...

  • Votes

    10

    Cyber Ark Collector

    I would like to request a collector for Cyber Ark. I have seen this asked by multiple customers.

  • Votes

    6

    Customer needs the ability to process EVTX files from netapp

    Sentinel should be capable of ingesting evtx files from netapp

  • Votes

    2

    Sentinel should have the capailty to add a tag within the agent ...

    Sentinel should have the capability to add a tag to devices and groups within the agent manager sentinel GUI Currently you can only add a tag in event sources. It would ...

  • Votes

    2

    exclude results in sentinel through the fields area

    it would be great if you could exclude results with a check mark in the refine fields area. instead of selecting what you want to see, you need to have the ability to ...

  • Votes

    3

    Browse to AD objects when creating correlation rule or lists.

    It would be good if we could leverage some of the technology in CG to browse to AD objects when creating correlation rule or lists.

  • Votes

    3

    Add the ID field to the message logs under all information

    I think it would beneficial to take the information from the TIPS area in sentinel and populate it in the details of the logs when you select all. Add the ID tag to the ...

  • Votes

    2

    brocade collector

    Sentinel does not currently have a brocade collector plugin.

  • Planned

    4

    Kaspersky Security Center Collector

    Kaspersky is one of the Top 5 Security Solutions on the market. Collectors for McAfee, Sophos, Symantec, Trend Micro exist, the creation of a Kaspersky Security Center ...

  • Planned

    8

    User behavior analytics(UBA)

    All leading SIEM products provide UBA; its a must feature for any modern-day SIEM. Unavailability of UBA is one of the major reason, competitors take edge in POC demos ...

  • Votes

    2

    Email zipped events in notification when correlation rule hits.

    We need the events to be zipped in mail notification as it becomes easier to analyze events if there are too many events.

  • Votes

    6

    Email zipped events in notification when correlation rule hits.

    We need the events to be zipped in mail notification as it becomes easier to analyze events if there are too many events.

  • Planned

    3

    Meraki Firewall Collector Plugin development

    The Cisco Meraki proprietary packet processing engine analyzes network traffic up to and including layer 7. Cisco Meraki's next generation firewall controls evasive, ...

  • Votes

    10

    make searching for "lateral movement" easier in the WebUI

    I really like the feature of being able clicking on fields to add a new criteria to the search query. When analyzing events, I often need to find similar events and do a ...