-
Votes
1
File Connector: File missing log event should contain event source ...
When file connector reports file missing. The event should contain event source information. This event is created in /var/opt/novell/sentinel/server0.0.log file.
Comments (0) | by: Timo S. | over a year ago | Last activity over a year ago | Status changed over a year ago | Integrations
-
Votes
6
F5 parser Event Name in clear text ...
Hi, This Collector has been added to support High Speed logging. The collector uses log message ID numbers as Event Name. This is not clear text and clear to understand. ...
Comments (0) | by: Timo S. | over a year ago | Last activity over a year ago | Status changed over a year ago | Integrations
-
Votes
4
Every JDBC database log source requires their own collector --> One ...
Hi, Currently JDBC database implementation needs a collector per single logsource. Even if the query is the same between servers. The offset value seems to be stored in ...
Comments (2) | by: Timo S. | over a year ago | Last activity over a year ago | Status changed over a year ago | Integrations
-
Votes
3
RedHat 8
Hi, RedHat 8 is published and many vendors and companies are planning to jump from RHEL6 to RHEL8. Is there any plans to make Sentinel8 RHEL8 compatible? -Br, TimoS
Comments (0) | by: Timo S. | over a year ago | Last activity over a year ago | Status changed over a year ago | Supported Platforms
-
Votes
3
MSG Field size to 16kB
The message field size should be bigger. Some of custom log event sources require bigger msg size.
Comments (0) | by: Timo S. | over a year ago | Last activity over a year ago | Status changed over a year ago | Installation/Deployment
-
Votes
2
CheckPoint R80.xx: LogExporter Collector is needed
CheckPoint has migrated from LEA-protocol to LogExporter (syslog) to integrate with SIEM products. At the same time the log event format has changed. Therefore a new ...
Comments (0) | by: Timo S. | over a year ago | Last activity over a year ago | Status changed over a year ago | Integrations
-
Votes
6
Possibility to restart individual Event source via CLI or REST API
Background: We have severe problems with File Connector log sources and have not get solution for that yet. For some reason file reading hangs occasionaly and never ...
Comments (0) | by: Kimmo J. | over a year ago | Last activity over a year ago | Status changed over a year ago | Configuration
-
Planned
2
Forcepoint's Data Leak Prevention (DLP) AP-Data collector
Forcepoint's Data Leak Prevention (DLP) AP-Data is well know in this space. With no Sentinel Collector, that's a significant blindspot of device and user activity in our ...
Comments (0) | by: Richard M. | over a year ago | Last activity over a year ago | Status changed over a year ago | Integrations
-
Planned
5
Forcepoint's web gateways AP-Web collector
Forcepoint's web gateways AP-Web is well know in this space. With no Sentinel Collector, that's a significant blindspot of device and user activity in our network.
Comments (1) | by: Richard M. | over a year ago | Last activity over a year ago | Status changed over a year ago | Integrations
-
Planned
6
Carbon Black Enterprise Response collector
Carbon Black Enterprise Response is well know in this space. With no Sentinel Collector, that's a significant blindspot of device and user activity in our network.
Comments (2) | by: Richard M. | over a year ago | Last activity over a year ago | Status changed over a year ago | Integrations
-
Votes
7
Enable Users to Toggle Case Sensitivity in Dynamic Lists
When leveraging values in dynamic lists, Sentinel currently enforces case sensitivity when using those values in correlation rules. In some cases, this can be misleading ...
Comments (1) | by: Eric L. | over a year ago | Last activity over a year ago | Status changed over a year ago | Configuration
-
Votes
8
Sentinel Windows Agent Should Handle Rotating Application Logs
Currently, the file connector has the capability to process rotating logs but that requires the ability to set up shares for Sentinel to access those logs remotely or ...
Comments (2) | by: Eric L. | over a year ago | Last activity over a year ago | Status changed over a year ago | Integrations
-
Votes
2
Ability to Export\Import Routing Rules
In some environments there may be many routing rules configured in Sentinel to do things like forward events via Sentinel link, tag events, or forward to another syslog ...
Comments (3) | by: Eric L. | over a year ago | Last activity over a year ago | Status changed over a year ago | Configuration
-
Votes
4
Use Email lists in correlation events
If you have multiple recipients for correlation event alarms, you have to create from CC's action manager an action for each recipient or add multiple addresses to the ...
Comments (2) | by: Jari V. | over a year ago | Last activity over a year ago | Status changed over a year ago | Other
-
Votes
2
Correlation dropped error reporter
It should be configurable per event source if you want it to alert if the events don't come to Sentinel in the correct time window. At the moment the system writes these ...
Comments (0) | by: Jari V. | over a year ago | Last activity over a year ago | Status changed over a year ago | Configuration
-
Votes
10
Postgres collector
Have the ability to collect, store, and read postgres logs via Sentinel. Working with the military, we have a requirement to store audit and database logs in 1 location. ...
Comments (4) | by: Shawn G. | over a year ago | Last activity over a year ago | Status changed over a year ago | Integrations
-
Votes
6
To support report for ISO 27002, year 2013.
Current version is ISO 27002, year 2005. When sentinel can support 2013?
Comments (1) | by: Fredric T. | over a year ago | Last activity over a year ago | Status changed over a year ago | Other
-
Votes
2
iSeries agent for Sentinel Agent Manager 8.0
Request to build iSeries agent for Sentinel Agent Manager 8.0
Comments (2) | by: Fredric T. | over a year ago | Last activity over a year ago | Status changed over a year ago | Integrations
-
Votes
3
VMware NSX Collector for Sentinel
There is no supported collector for VMware NSX in Sentinel. Create a collector that supports the VMware NSX platform/technology. VMware's Network virtualization ...
Comments (1) | by: Anthony D. | over a year ago | Last activity over a year ago | Status changed over a year ago | Integrations
-
Votes
6
WTMP Agent RPM
Worlking at Worldline in a Sentinel project. Worldline has already a Linuy based "Siem" for Linux events, that the buils on Linux scripting. Now they build a Sentinel ...
Comments (2) | by: Ulrich S. | over a year ago | Last activity over a year ago | Status changed over a year ago | Installation/Deployment