• Votes

    5

    Make correlation event retention length configurable separately from ...

    Provide the means to configure correlation event retention to a different period than data event retention in order to prevent the PostgreSQL from growing too large.

  • Votes

    3

    Have a deployment or installation guide specific for AWS

    It would be great to have a specific deployment or installation guide with all steps needed to be followed to install Sentinel on AWS. Today many customers are moving ...

  • Votes

    2

    Better LDAP integration

    Currently the LDAP integration is extremely basic. It requires far too much work to get it to work with an LDAP load balancer. The best LDAP integrations automatically ...

  • Votes

    2

    Sentinel 8.2.2.0 database upgrade failure due to older orphaned jar ...

    During an upgrade from Sentinel 8.2.0.0 the database upgrade failed, after the main Sentinel upgrade failed. After investigation, it was determined that there were some ...

  • Votes

    2

    Fix your post 8.2.2.0 installer to require 4 CPUs

    Sentinel 8.2.2.0 will not successfully install on Linux without 4 cores assigned to the box. I recently spent around a week trying to get a clean 8.2.2.0 install to work ...

  • Votes

    1

    Integrate the 9443 console certificate mechanism of the Sentinel 8.2.0 ...

    Appliances created with SUSE studio have a security certificate mechanism integrated into the port 9443 administration console. This mechanism greatly simplifies the ...

  • Votes

    1

    Fix your post 8.2.2.0 installer to require 4 CPUs

    Sentinel 8.2.2.0 will not successfully install on Linux without 4 cores assigned to the box. I recently spent around a week trying to get a clean 8.2.2.0 install to work ...

  • Votes

    4

    Export configuration in clear text

    Customer HELAB need a tool to export the complete configuration in clear text or pdf to have a documentation of their system. This is needed because of regulation ...

  • Votes

    5

    EVT/EVTX file via Agent Manager Agent

    In agent manager you can read a Single Line Log. It would be a great enhancement to read also evt/evtx files, because there are several software products that write ...

  • Votes

    1

    Option to Stopp Collector and delete all incoming Events

    When a collector ist stopped the incoming events are stored (PageFiles) and a filesystem can be filled with this files. So an second option would be very usefull: The ...

  • Votes

    1

    Read SAP Security Audit Log via RSAU_API_GET_ALERTS

    From SAP Note 2191612 - FAQ | Use of Security Audit Log as of SAP NetWeaver 7.50 42. Can recorded events be promptly transferred to a central alert cockpit? The RFC ...

  • Votes

    7

    Customisation WebUI

    Like in other Soltware solutions there should be a possibility to customise the Login Page of Sentinel. There should be two things: - customize the login page with the ...

  • Votes

    6

    WTMP Agent RPM

    Worlking at Worldline in a Sentinel project. Worldline has already a Linuy based "Siem" for Linux events, that the buils on Linux scripting. Now they build a Sentinel ...

  • Votes

    3

    bintec Collector

    A collector for bintec router/VPN devices would be fine

  • Votes

    7

    CheckPoint LEA Connector missing critical pieces of information

    I've spotted some flaws on CheckPoint collector. I'm giving one example from blade "URL Filtering" in CheckPoint These fields are : appi_name, matched_category, ...

  • Votes

    1

    Disable User - Improved

    Current Process: Edit User Disable user account Save ERROR Save user failed ERROR Passwords don't match *Have to set password just to disable. Why? Proposed Process 1: ...

  • Votes

    1

    ArcSight CEF CustomFieldMap

    Need to include CEF Custom String and Number Labels out of the box. Labels are different for each product. ~~Sentinel Event Field~~,~~Input Record Field~~ ...

  • Votes

    13

    Multiple roles for users

    Current user role allocation supports well administration, but how to allocate rights easily in user environment (for users that only go there to search events and run ...

  • Votes

    2

    Extend windows event logs possibilities in SAM

    It could be interesting to extend windows logs (currently limited to secuity ad system logs) to others services/software like sysmon logs; powershell logs, RDP logs in ...

  • Votes

    6

    Support for eStreamer via Cisco nCore client

    Cisco is in the process of releasing a client for collecting via eStreamer that is supported and maintained by them rather than asking their consumers to write custom ...