• Votes

    3

    Sentinel plugin for Log4j

    It is a popular implementation to log application data

  • Votes

    1

    Symantec DPL Connector

    A connector to connect Symantec Data Loss Protection is urgently needed. Clients have requested it.

  • Votes

    0

    "Status Details" statistics do not persist on Sentinel service restart

    Within the Sentinel Control Center (SCC) --> Event Source Management --> Live View... --> Table tab --> expand any Collector Manager. The statistics do not persist upon ...

  • Votes

    2

    Detect anomaly's in user logon activity

    The ability to detect anomaly's in user logon activity, ie logging on to a system they have never used before.

  • Votes

    6

    Support Wildcarding In Dynamic Lists

    Dynamic Filters should allow the same CIDR notation and wildcarding that Lucene allows specifically for IP addresses. Should also allow ranges like 10.14.1.[1-50]

  • Votes

    3

    Microsoft ATA

    Create and release to test a new Microsoft ATA collector plugin for Sentinel 7/8 to integrate with leading edge threat analytics platforms

  • Planned

    10

    Support for Oracle Service names instead of SID

    A company may standardize on using service names because when using Oracle RAC. The Sentinel Data Synchronization to Oracle feature is only possible by using the SID of ...

  • Votes

    2

    support pure-ftpd access log

    I hope to be able to target pure-ftp log to parsing, because many of my customers use novell ftp to access nss volume, and novell ftp uses pure-ftpd service, so audit ...

  • Planned

    4

    Sentinel User Permissions for Web Interface and REST API procedure ...

    A recent investigation into the automation of creating new event source objects within Sentinel via external sources has revealed that the permissions necessary to invoke ...

  • Planned

    12

    Add ability to WECS to read from newer "Vista-style" Event Logs

    Sentinel lacks an ability that many of your leading competitors offer to grab events from the newer "Windows Vista" style Event Logs on all new Windows operating systems ...

  • Planned

    7

    Mechanism to customize, per event type, fields of interest that ...

    Sentinel needs a means to get common-interest fields to automatically show-up when “More” is selected on an individual event or “Show more details” is ...

  • Planned

    6

    Airwatch Collector

    AirWatch is probably one of if not "the" top MDM solutions on the market today. With no Sentinel Collector, that's a significant blindspot of device and user activity in ...

  • Planned

    12

    Time scheduling for Sentinel connectors

    Connected systems like databases or others have maintenance times during the night or weekend, when they are shut down. Installed connectors (for DB2 for instance) then ...

  • Planned

    7

    Out of box Reports extraction Format

    At this time reports (out of box)can only be exported from the SIEM as PDF files. It would be great if we could get those reports in CSV format as well.

  • Votes

    4

    Syslog over TCP needs to recognize NULL characters as message ...

    Some products like Juniper Netscreen use NULL character as a Syslog message delimiter. Our Syslog connector does not treat NULL char as a delimiter and as a result, ...

  • Votes

    2

    Supporting Syslog TCP with Octet Counting Framing

    This framing mode is yet to have a wide acceptance. Also, the latest rsyslog does have an optional mode for this --> ...

  • Votes

    7

    VMWare vCenter logs

    vCenter makes most of it's logging available in the Windows Event log for software-based installations, and via Syslog for appliance (VCSA) installations, at least from ...

  • Votes

    6

    Normalize severity against a standard severity scale rather than ...

    Different vendors attribute different severities to certain types of events based on their own internal way of looking at the data. When Sentinel sets the severity, it ...

  • Votes

    3

    Enable Postgresql DB storage to use an different filesystem/partition ...

    When the DB is on the same store as the event store, either the DB or the event store overrunning available storage can create problems for the other store. Also, ...

  • Votes

    2

    Request for incremental backup options in the backup script for ...

    Provide the backup script the ability to create an differential (incremental) update of the backup since time the last backup was performed. This reduces the time and ...