• Votes

    13

    Need Collector Plugin for Splunk

    Hi, I have an issues when Splunk SIEM forwards the logs towards Sentinel Collector. I received the logs coming from 1 node which have multiple logs per devices(Palo Alto ...

  • Votes

    13

    Multiple roles for users

    Current user role allocation supports well administration, but how to allocate rights easily in user environment (for users that only go there to search events and run ...

  • Planned

    12

    Time scheduling for Sentinel connectors

    Connected systems like databases or others have maintenance times during the night or weekend, when they are shut down. Installed connectors (for DB2 for instance) then ...

  • Planned

    12

    Add ability to WECS to read from newer "Vista-style" Event Logs

    Sentinel lacks an ability that many of your leading competitors offer to grab events from the newer "Windows Vista" style Event Logs on all new Windows operating systems ...

  • Votes

    12

    Certify Sentinel for High availability on Red Hat Linux

    High availability/Clustering for Sentinel is only supported and certified on SLES or SLES appliances. There is no supported high availability option available for ...

  • Votes

    11

    Need Collector Plugin for Event Source from SentinelOne product

    Hi, I have forwarded log from SentinelOne device via syslog message. The problem is, the Event Source naming display incorrectly then it should be. It produces multiple ...

  • Votes

    10

    Cyber Ark Collector

    I would like to request a collector for Cyber Ark. I have seen this asked by multiple customers.

  • Votes

    10

    make searching for "lateral movement" easier in the WebUI

    I really like the feature of being able clicking on fields to add a new criteria to the search query. When analyzing events, I often need to find similar events and do a ...

  • Votes

    10

    Postgres collector

    Have the ability to collect, store, and read postgres logs via Sentinel. Working with the military, we have a requirement to store audit and database logs in 1 location. ...

  • Votes

    10

    Make Sentinel 8 CentOS 7 "compatible"

    Hi, Sometimes I want to install Sentinel to CentOS (e.g no hassle with licensing in labs). Sentinel 7.4 series run fine in Centos 6.x. Would developers make Sentinel 8 ...

  • Planned

    10

    Support for Oracle Service names instead of SID

    A company may standardize on using service names because when using Oracle RAC. The Sentinel Data Synchronization to Oracle feature is only possible by using the SID of ...

  • Votes

    9

    pseudonymization of user identifiers

    Data privacy laws and regulations in certain areas prohibit the use of subject’s real names or identifiers which can easily be attributed to a subject (e.g. account names ...

  • Votes

    9

    Search results sorting

    Currenty search results are sorted descending according to Event Time. But when two same events have the Event Time parameter same, the order of these events is wrong. ...

  • Votes

    9

    CM backup

    Customers are asking why we do not have official backup/restore script or other CLI method to export/import CM configuration.

  • Votes

    8

    Sentinel Windows Agent Should Handle Rotating Application Logs

    Currently, the file connector has the capability to process rotating logs but that requires the ability to set up shares for Sentinel to access those logs remotely or ...

  • Planned

    8

    Support both IPv4 and IPv6 for IP2Location

    IP2Location offers IPv4 and IPv6 as separate databases (e.g. DB5 & DB5IPV6) so the feed should be capable of processes both CSV's into Map without the need for complex ...

  • Planned

    8

    User behavior analytics(UBA)

    All leading SIEM products provide UBA; its a must feature for any modern-day SIEM. Unavailability of UBA is one of the major reason, competitors take edge in POC demos ...

  • Votes

    8

    Customisation WebUI

    Like in other Soltware solutions there should be a possibility to customise the Login Page of Sentinel. There should be two things: - customize the login page with the ...

  • Votes

    8

    Schedule download for scp or/and sshfs for file connector

    SCP option in the file connector should have schedule/recurring download option. sshfs together with CIFS and NFS, would be very useful option too.

  • Votes

    8

    A way to migrate event and rawdata from Sentinel installation to ...

    Currently there is no way to migrate event and rawdata between separate Sentinel Installations. The current "Find data" operability in Data Restoration supports only ...