• Votes

    4

    Syslog over TCP needs to recognize NULL characters as message ...

    Some products like Juniper Netscreen use NULL character as a Syslog message delimiter. Our Syslog connector does not treat NULL char as a delimiter and as a result, ...

  • Votes

    6

    Possibility to restart individual Event source via CLI or REST API

    Background: We have severe problems with File Connector log sources and have not get solution for that yet. For some reason file reading hangs occasionaly and never ...

  • Votes

    2

    Kafka connector

    Our client has centralized data storage created on Hadoop. They are transferring data from self designed applications through Apache Kafka. It would be nice to have ...

  • Votes

    1

    IBM zOS Collector

    IBM zOS mainframe collector to help parse and correlate the logs sent to sentinel. This type of collector would help translate RACF logs and Type80 send logs in CEF ...

  • Votes

    5

    Update SSL Certificates

    Please either allow or build in a function to allow the update of an SSL certificate issued from either a third party CA or an internal CA for website functionality. In ...

  • Votes

    6

    File Connector - Keep file offset data stored while moving log source ...

    Now, when moving file log source from cm to another it does not store offset data. This should be fixed. -Br, TimoS

  • Votes

    2

    Correlation Rules Firing - Scheduled Email Alerts

    The ability to have emails from correlation rule event firing to go to a different (or additional) email address during a certain time period would be invaluable. e..g ...

  • Planned

    10

    Support for Oracle Service names instead of SID

    A company may standardize on using service names because when using Oracle RAC. The Sentinel Data Synchronization to Oracle feature is only possible by using the SID of ...

  • Planned

    8

    User behavior analytics(UBA)

    All leading SIEM products provide UBA; its a must feature for any modern-day SIEM. Unavailability of UBA is one of the major reason, competitors take edge in POC demos ...

  • Votes

    6

    Normalize severity against a standard severity scale rather than ...

    Different vendors attribute different severities to certain types of events based on their own internal way of looking at the data. When Sentinel sets the severity, it ...

  • Votes

    1

    General users should be able to view Health Status Info

    General users should be able to view but not edit or modify the following collection - Overview & Event sources Storage - Health, report jobs, search jobs When ...

  • Votes

    3

    Microsoft ATA

    Create and release to test a new Microsoft ATA collector plugin for Sentinel 7/8 to integrate with leading edge threat analytics platforms

  • Votes

    6

    Support Wildcarding In Dynamic Lists

    Dynamic Filters should allow the same CIDR notation and wildcarding that Lucene allows specifically for IP addresses. Should also allow ranges like 10.14.1.[1-50]

  • Votes

    2

    iSeries agent for Sentinel Agent Manager 8.0

    Request to build iSeries agent for Sentinel Agent Manager 8.0

  • Votes

    4

    webhelper to interact with REST api from collectors and actions

    If one wants to interact with Sentinel's REST api a https connection need to be established and authenticated. This can be cumbersome from an action or collector and ...

  • Planned

    4

    notification on alert creation or owner change

    there should be an option to notify the owner if an alert is assigned.

  • Votes

    3

    Data Synchronization enhancement

    Enhance the data synchronization feature to allow the user to specify a start and finish date. Additionally, allow the user to kick-off the job on a specific date/time ...

  • Votes

    4

    Samba v2 and v3 support in file connector

    File connector should be able to use SMB v2 and v3.

  • Votes

    2

    Ability to Export\Import Routing Rules

    In some environments there may be many routing rules configured in Sentinel to do things like forward events via Sentinel link, tag events, or forward to another syslog ...

  • Votes

    3

    bintec Collector

    A collector for bintec router/VPN devices would be fine