• Votes

    6

    To support report for ISO 27002, year 2013.

    Current version is ISO 27002, year 2005. When sentinel can support 2013?

  • Votes

    6

    Possibility to restart individual Event source via CLI or REST API

    Background: We have severe problems with File Connector log sources and have not get solution for that yet. For some reason file reading hangs occasionaly and never ...

  • Votes

    6

    Asset mapping for hostnames

    Current Asset mapping works only for IP and tenant name as a keys. But some customers use hostnames as the asset identification as they use DHCP servers. It is not ...

  • Votes

    6

    Email zipped events in notification when correlation rule hits.

    We need the events to be zipped in mail notification as it becomes easier to analyze events if there are too many events.

  • Votes

    5

    Make correlation event retention length configurable separately from ...

    Provide the means to configure correlation event retention to a different period than data event retention in order to prevent the PostgreSQL from growing too large.

  • Votes

    5

    EVT/EVTX file via Agent Manager Agent

    In agent manager you can read a Single Line Log. It would be a great enhancement to read also evt/evtx files, because there are several software products that write ...

  • Votes

    5

    Sentinel does not provide an explicit logout message

    Please provide the following enhancement to the NetIQ Sentinel web interface: An explicit logout message indicating that the authenticated communications session has been ...

  • Votes

    5

    Dashboard / Visualization from other Sentine Server

    I need an option to use the Data Federation not only on searches and Reports, but also on Dashboards and Visualization. This is very important for scalability issues to ...

  • Votes

    5

    Aruba Mobility Controller with younger OS

    We downloaded the latest SmartConnector package (ArcSight-7.11.0.8139.0-Connector-Linux64.bin). Customer would like to collect data (with Aruba SC) from their Aruba ...

  • Votes

    5

    allow additional links to be added to app navigation bar

    The left nav bar in the Sentinel app currently has links for home, main, search and (at the bottom) security health. This leaves a lot of room that could be used to add ...

  • Votes

    5

    Import event sources

    We have more than 200 servers which need to be created in multiple collectors. It would be great to import them via a CSV.

  • Votes

    5

    Agent Manager Agent shoud send Heartbeat Events to detekt that it is ...

    There should be a possiblity to detect that an Agent Manager Agent is running independent from sending events to Sentinel. I think one possibilty would be to have a ...

  • Votes

    5

    Tenant based roles to allow to run remote searches or manage ...

    Customer reported that they are planning to deploy a multi tenant Sentinel system. They would like to use multi-tier architecture, where they have multiple Sentinel for ...

  • Votes

    5

    Need some more granularity for user permissions

    There are some features/functions, which only accessible for "super-users", e.g. creating/maintaining Actions, configuring Storage, etc... Our main issue currently, how ...

  • Votes

    5

    Update SSL Certificates

    Please either allow or build in a function to allow the update of an SSL certificate issued from either a third party CA or an internal CA for website functionality. In ...

  • Votes

    5

    Permissions to Security Intelligence Boards

    Changing the permission structure: Now: Only access to all events for a user and permissions to SI boards are possible. If you limit the event view with a filter you ...

  • Planned

    5

    Forcepoint's web gateways AP-Web collector

    Forcepoint's web gateways AP-Web is well know in this space. With no Sentinel Collector, that's a significant blindspot of device and user activity in our network.

  • Planned

    5

    Extend Feed Frequency Options

    At the moment the minimum Feed frequency is Weekly. Considering IP2Location only updates their databases once a month, this weekly minimum is a waste of resources to ...

  • Votes

    4

    Fix your post 8.2.2.0 installer to require 4 CPUs

    Sentinel 8.2.2.0 will not successfully install on Linux without 4 cores assigned to the box. I recently spent around a week trying to get a clean 8.2.2.0 install to work ...

  • Votes

    4

    Export configuration in clear text

    Customer HELAB need a tool to export the complete configuration in clear text or pdf to have a documentation of their system. This is needed because of regulation ...