• Votes

    1

    ArcSight CEF CustomFieldMap

    Need to include CEF Custom String and Number Labels out of the box. Labels are different for each product. ~~Sentinel Event Field~~,~~Input Record Field~~ ...

  • Votes

    1

    User Inactivity Timeout

    Need User Inactivity Timeout option. Session timeout exists but will kill session while user is actively working. GUI 'Security' section preferred.

  • Votes

    1

    Disable User - Improved

    Current Process: Edit User Disable user account Save ERROR Save user failed ERROR Passwords don't match *Have to set password just to disable. Why? Proposed Process 1: ...

  • Votes

    1

    Limit concurrent user sessions

    Need option to limit concurrent user sessions in Sentinel Client Request

  • Votes

    1

    Allow to comment on each event in an alert separately

    In some cases to differentiate events that are attached to an alert analysts have to document some information for each event separately (i.e. each event having different ...

  • Votes

    2

    Extend windows event logs possibilities in SAM

    It could be interesting to extend windows logs (currently limited to secuity ad system logs) to others services/software like sysmon logs; powershell logs, RDP logs in ...

  • Votes

    3

    Appliance based Elastic Nodes for event visualisation

    The requirement to build your own elastic nodes to provide event visualisation, means this is not a full product, this then requires additional Server OS licencing. All ...

  • Votes

    5

    Aruba Mobility Controller with younger OS

    We downloaded the latest SmartConnector package (ArcSight-7.11.0.8139.0-Connector-Linux64.bin). Customer would like to collect data (with Aruba SC) from their Aruba ...

  • Votes

    5

    Dashboard / Visualization from other Sentine Server

    I need an option to use the Data Federation not only on searches and Reports, but also on Dashboards and Visualization. This is very important for scalability issues to ...

  • Votes

    1

    File Connector: File missing log event should contain event source ...

    When file connector reports file missing. The event should contain event source information. This event is created in /var/opt/novell/sentinel/server0.0.log file.

  • Votes

    1

    Event Export Filters

    When exporting the Events from a Search query, there is only "Select All"/"Clear All". More often than not, a user would export the same fields for queries they run ...

  • Votes

    2

    Adding comments/notes to an Event Routing Rule

    Our customer would like to add note (or comment) to an Event Routing Rule, but currently it is not possible. Please, add this new field to Sentinel

  • Votes

    5

    Sentinel does not provide an explicit logout message

    Please provide the following enhancement to the NetIQ Sentinel web interface: An explicit logout message indicating that the authenticated communications session has been ...

  • Votes

    3

    Improve NoDataAlert

    Is there a way to improve this event? Currently it gets logged as a generic 'Internal' event and all of the data is in the message field with none of it parsed out. ...

  • Votes

    2

    Palo Alto NGFW

    Today, the operation system version of the Palo Alto NGFW is PAN-OS 8.1. However, the version we support is 6.0 in https://www.netiq.com/support/sentinel/plugins/ Do we ...

  • Votes

    2

    Certify the use of BigIP together with Sentinel, SAM and UAM

    Because a SAM Central Computer only can connect to one Collector Manager. It would be nice if it was supported adding a BigIP between SAMservers and Collector Managers. ...

  • Votes

    3

    Change Guardian Agent install

    In CG version 5.1 there is no more build in option to do a agent install via software distribution software. There is a cool solution: ...

  • Votes

    7

    Configurable Alarm View

    there is only a non-configurable Alarm view. It would be great to have it configurabel to have other/more table rows. e.g. in the Alarm View list it would very helpful ...

  • Votes

    6

    Ability to recreate an empty database (Postgres, mongo)

    Normally running the 'backup_util.sh' is the part of the daily routine to make a backup about the required components (mainly the config, SI, alerts, etc...) In a case ...

  • Votes

    1

    Customer needs Microsoft Radius data to be parsed correctly.

    A customer has Microsoft Radius server and they need to be able to search on the mac address. Unfortunately all other systems use a format like this: 00:AA:00:12:34:56, ...