• Votes

    4

    Add ability to customize Sentinel report format

    When reports are generated in Sentinel, you do not have a choice of how the report is formatted. For example, customer wants to display data in a bar graph format versus ...

  • Votes

    4

    Add FQDN host fields

    Currently Sentinel splits fully qualified DNS names into a Hostname and the Domain part. That makes it diffucult to use thread intelligence feeds in dynamic lists, as ...

  • Votes

    4

    Alphabetical ordering of actions in action manager

    it is sometimes difficult to find an action in Action manager. could be interesting to order alphabeticaly

  • Votes

    4

    Every JDBC database log source requires their own collector --> One ...

    Hi, Currently JDBC database implementation needs a collector per single logsource. Even if the query is the same between servers. The offset value seems to be stored in ...

  • Planned

    4

    Kaspersky Security Center Collector

    Kaspersky is one of the Top 5 Security Solutions on the market. Collectors for McAfee, Sophos, Symantec, Trend Micro exist, the creation of a Kaspersky Security Center ...

  • Planned

    4

    Support security features provided by SNMP v3

    Authentication in SNMP v1 and v2 is nothing but community string sent in clear text. SNMPv3 does not use community strings, but uses password based authentication and ...

  • Votes

    4

    Samba v2 and v3 support in file connector

    File connector should be able to use SMB v2 and v3.

  • Votes

    4

    Syslog over TCP needs to recognize NULL characters as message ...

    Some products like Juniper Netscreen use NULL character as a Syslog message delimiter. Our Syslog connector does not treat NULL char as a delimiter and as a result, ...

  • Votes

    4

    webhelper to interact with REST api from collectors and actions

    If one wants to interact with Sentinel's REST api a https connection need to be established and authenticated. This can be cumbersome from an action or collector and ...

  • Votes

    4

    Use Email lists in correlation events

    If you have multiple recipients for correlation event alarms, you have to create from CC's action manager an action for each recipient or add multiple addresses to the ...

  • Planned

    4

    notification on alert creation or owner change

    there should be an option to notify the owner if an alert is assigned.

  • Planned

    4

    Sentinel User Permissions for Web Interface and REST API procedure ...

    A recent investigation into the automation of creating new event source objects within Sentinel via external sources has revealed that the permissions necessary to invoke ...

  • Planned

    4

    Support IPv6 through and through

    Instead of hacking the system, such as TID 7016555, to make any use of IPv6, Sentinel should not only accept IPv6 syntaxes, but store and parse them in such a way that ...

  • Votes

    3

    Better LDAP integration

    Currently the LDAP integration is extremely basic. It requires far too much work to get it to work with an LDAP load balancer. The best LDAP integrations automatically ...

  • Votes

    3

    MSG Field size to 16kB

    The message field size should be bigger. Some of custom log event sources require bigger msg size.

  • Votes

    3

    RedHat 8

    Hi, RedHat 8 is published and many vendors and companies are planning to jump from RHEL6 to RHEL8. Is there any plans to make Sentinel8 RHEL8 compatible? -Br, TimoS

  • Votes

    3

    Configuring Sentinel Web Console Settings From Red Hat/RestAPI

    Please provide the means to automate or configure the following Sentinel Web Console settings via Red Hat or RestAPI: -Secondary Storage location -Primary Storage ...

  • Votes

    3

    Have a deployment or installation guide specific for AWS

    It would be great to have a specific deployment or installation guide with all steps needed to be followed to install Sentinel on AWS. Today many customers are moving ...

  • Votes

    3

    bintec Collector

    A collector for bintec router/VPN devices would be fine

  • Votes

    3

    Improve NoDataAlert

    Is there a way to improve this event? Currently it gets logged as a generic 'Internal' event and all of the data is in the message field with none of it parsed out. ...