• Votes

    2

    syslog connector to route events based on CEF Vendor Product

    Add an an additional “CEFVendorProduct” Package Policy, which works just like “Application ID” but uses the two CEF header fields for routing decision. The precedence of ...

  • Votes

    1

    Salesforce collector

    Micro Focus should have a Salesforce collector. this from Salesforce describes a very typical usecase: ...

  • Votes

    2

    Micro Focus should have a MS Dynamics collector +

    Micro Focus should have a collector that supports MS Dynamics in the cloud but preferrably all services that a Sentinel customer is using from MS Azure. Here's MS page ...

  • Votes

    2

    Kafka connector

    Our client has centralized data storage created on Hadoop. They are transferring data from self designed applications through Apache Kafka. It would be nice to have ...

  • Votes

    6

    Asset mapping for hostnames

    Current Asset mapping works only for IP and tenant name as a keys. But some customers use hostnames as the asset identification as they use DHCP servers. It is not ...

  • Votes

    9

    Search results sorting

    Currenty search results are sorted descending according to Event Time. But when two same events have the Event Time parameter same, the order of these events is wrong. ...

  • Votes

    13

    Multiple roles for users

    Current user role allocation supports well administration, but how to allocate rights easily in user environment (for users that only go there to search events and run ...

  • Votes

    8

    A way to migrate event and rawdata from Sentinel installation to ...

    Currently there is no way to migrate event and rawdata between separate Sentinel Installations. The current "Find data" operability in Data Restoration supports only ...

  • Votes

    6

    File Connector - Keep file offset data stored while moving log source ...

    Now, when moving file log source from cm to another it does not store offset data. This should be fixed. -Br, TimoS

  • Votes

    6

    Checksum for eventdata

    Currently Sentinel creates checksum only for rawdata in secondary storage. There are some cases where checksum is needed to event data as well. -Br, TimoS

  • Votes

    14

    EPS level alert, monitoring and visualization

    Currently Sentinel does not have any method to monitor EPS levels properly. It would good to have some way to monitor EPS levels and have an alert if e.g. system ...

  • Votes

    10

    Make Sentinel 8 CentOS 7 "compatible"

    Hi, Sometimes I want to install Sentinel to CentOS (e.g no hassle with licensing in labs). Sentinel 7.4 series run fine in Centos 6.x. Would developers make Sentinel 8 ...

  • Votes

    3

    Make Data Source selection permanent

    Data Source selection should be made permanent so that it is selected every time you make a search. Now it should be manually ticked every time you make a new search.

  • Votes

    1

    File Connector: File missing log event should contain event source ...

    When file connector reports file missing. The event should contain event source information. This event is created in /var/opt/novell/sentinel/server0.0.log file.

  • Votes

    6

    F5 parser Event Name in clear text ...

    Hi, This Collector has been added to support High Speed logging. The collector uses log message ID numbers as Event Name. This is not clear text and clear to understand. ...

  • Votes

    4

    Every JDBC database log source requires their own collector --> One ...

    Hi, Currently JDBC database implementation needs a collector per single logsource. Even if the query is the same between servers. The offset value seems to be stored in ...

  • Votes

    3

    RedHat 8

    Hi, RedHat 8 is published and many vendors and companies are planning to jump from RHEL6 to RHEL8. Is there any plans to make Sentinel8 RHEL8 compatible? -Br, TimoS

  • Votes

    3

    MSG Field size to 16kB

    The message field size should be bigger. Some of custom log event sources require bigger msg size.

  • Votes

    2

    CheckPoint R80.xx: LogExporter Collector is needed

    CheckPoint has migrated from LEA-protocol to LogExporter (syslog) to integrate with SIEM products. At the same time the log event format has changed. Therefore a new ...

  • Votes

    6

    Possibility to restart individual Event source via CLI or REST API

    Background: We have severe problems with File Connector log sources and have not get solution for that yet. For some reason file reading hangs occasionaly and never ...