Sentinel 22.214.171.124 includes new features, improves usability, and resolves several previous issues.
Many of these improvements were made in direct response to suggestions from our customers. We thank you for your time and valuable input. We hope you continue to help us ensure that our products meet all your needs. You can post feedback in the Sentinel forum, our online community that also includes product information, blogs, and links to helpful resources. You can also share your ideas for improving the product in the Ideas Portal.
The documentation for this product is available in HTML and PDF formats on a page that does not require you to log in. If you have suggestions for documentation improvements, click the comment icon on any page in the HTML version of the documentation posted at the Sentinel Documentation page. To download this product, see the Product Download website.
The following sections outline the key features provided by this version, as well as issues resolved in this release:
Sentinel 126.96.36.199 now includes a new signing certificate used to sign Sentinel JAR files. The older signing certificate has expired. Therefore, on Sentinel versions prior to 188.8.131.52, you will not be able to apply hot fixes until you upgrade to Sentinel 184.108.40.206.
For appliance users who are upgrading their appliances from SLES 11 SP4 to SLES 12 SP3 for the first time, a newer version of the post-upgrade utility is available. The 220.127.116.11 version of the post-upgrade utility contains an updated list of RPMs required for a successful upgrade of the operating system. For more information about upgrading the operating system, see Upgrading the Operating System
Sentinel 18.104.22.168 includes software fixes that resolve the following issues:
Issue: Creating a new instance of Syslog Integrator and configuring it to send events using the) option, splits a CEF event into multiple events
Fix: A new instance of Syslog Integrator now sends a CEF event in the expected format. (Bug 1094066)
Internal events include user information.(Bug 1092785)
Issue: Launching Sentinel Appliance Management Console after installing or upgrading to Sentinel 8.2 displays the 500 Internal Server Error. (Bug 1104511)
Fix: You will no longer see the 500 Internal Server Error.
SLES 12 SP3 is a minimum requirement for appliance installations of Sentinel 22.214.171.124. For more information about hardware requirements, supported operating systems, and browsers, see the Technical Information for Sentinel page.
For traditional installations, you can upgrade to Sentinel 126.96.36.199 from Sentinel 188.8.131.52 and later. For appliance installations, you must first upgrade Sentinel to version 8.2 and upgrade the operating system to SLES 12 SP3 because Sentinel 184.108.40.206 updates are available only on the SLES 12 channel.
NOTE:Sentinel leverages Kibana for visualizing and searching events in dashboards. Elasticsearch and Kibana versions have been upgraded in Sentinel 8.2. Therefore, you must do the following after upgrading to 8.2:
If you have any custom dashboards, you need to recreate them after upgrading Sentinel.
Some of the Sentinel dashboards that leverage Kibana do not load after you upgrade to Sentinel 220.127.116.11, from versions prior to 8.2. This issue occurs because Elasticsearch and Kibana versions have been upgraded in Sentinel 8.2, and the existing Kibana index file is not compatible with the upgraded versions of Elasticsearch and Kibana. To fix this issue, you must manually delete the existing Kibana index file and recreate a new Kibana index file. For more information, see the Knowledge Base Article 7022736.
You do not have to repeat these instructions after upgrading to 18.104.22.168.
For information about upgrading to Sentinel 22.214.171.124, see the Sentinel Installation and Configuration Guide.
Micro Focus strives to ensure our products provide quality solutions for your enterprise software needs. The following known issues are currently being researched. If you need further assistance with any issue, please contact Technical Support.
The Java 8 update included in Sentinel might impact the following plug-ins:
Cisco SDEE Connector
SAP (XAL) Connector
For any issues with these plug-ins, we will prioritize and fix the issues according to standard defect-handling policies. For more information about support polices, see Support Policies.
Issue: In Hyper-V Server 2016, Sentinel appliance does not start when you reboot it and displays the following message:
A start job is running for dev-disk-by\..
This issue occurs because the operating system modifies the disk UUID during installation. Therefore, during reboot it cannot find the disk.
Workaround: Manually modify the disk UUID. For more information, see Knowledge Base Article 7023143.
Issue: Vulnerability scans report issues, such as the following message, with a vulnerable version of jquery:
The file 'jquery-1.11.3.min.js' includes a vulnerable version of the library 'jquery'.
The noted vulnerability affects only versions 1.8.0 to 1.12.0, but the reported URL redirects to a much newer version of jquery (3.x). (Bug 1094393)
Workaround: Ignore the issue since it is a false positive.
Issue: When you upgrade to Sentinel 8.2 HA appliance, Sentinel displays the following error:
Installation of novell-SentinelSI-db-126.96.36.199-<version> failed: with --nodeps --force) Error: Subprocess failed. Error: RPM failed: Command exited with status 1. Abort, retry, ignore? [a/r/i] (a):
Workaround: Before you respond to the above prompt, perform the following:
Start another session using PuTTY or similar software to the host where you are running the upgrade.
Add the following entry in the /etc/csync2/csync2.cfg file:
Remove the sentinel folder from /var/opt/novell:
rm -rf /var/opt/novell/sentinel
Return to the session where you had initiated the upgrade and enter r to proceed with the upgrade.
Issue: Installation of Collector Manager and Correlation Engine appliance fails in MFA mode if the operating system language is other than English. (Bug 1045967)
Workaround: Install Collector Manager and Correlation Engine appliances in English. After the installation is complete, change the language as needed.
Issue: An issue prevents Internet Explorer 11 from being able to open the Event Visualization dashboard. (Bug 981308)
Workaround: Use a different browser to view or modify the visualization dashboard.
Issue: A change to password storage in Sentinel 7.4 SP1 causes the following error to display when upgrading the appliance from versions prior to 7.4 SP1:
Failed to set encrypted password
Workaround: The warning is expected and you can safely ignore it. There is no impact to the upgrade.
Issue: Theand buttons in the appliance installation screens do not appear or are disabled in some cases, such as the following:
When you clickfrom the Sentinel precheck screen to edit or review the information in the Sentinel Server Appliance Network Settings screen, there is no button to proceed with the installation. The button allows you to only edit the specified information.
If you have specified incorrect network settings, the Sentinel Precheck screen indicates that you cannot proceed with the installation due to incorrect network information. There is nobutton to go the previous screen to modify the network settings.
Workaround: Restart the appliance installation.
Issue: Sentinel displays the following message during start up in the server.log file:
Value for attribute rv43 is too long
Workaround: Ignore the exception. Although the message is displayed, Sentinel works as expected.
Issue: When there is a large number of events whose retention period has expired and SSDM tries to delete those events from Elasticsearch, the following exception is displayed in the server.log file:
java.net.SocketTimeoutException: Read timed out
Workaround: Ignore the exception. This exception occurs due to the time taken to delete the large amount of data. Although the exception is displayed, SSDM successfully deletes the events from Elasticsearch.
Issue: Sentinel Generic Collector performance degrades when Generic Hostname Resolution Service Collector is enabled on Microsoft Active Directory and Windows Collector. EPS decreases by 50% when remote Collector Managers send events. (Bug 906715)
Issue: If you manually install and enable time synchronization in open-vm-tools, they periodically synchronize time between the Sentinel appliance (guest) and the VMware ESX server (host). These time synchronizations can result in moving the guest clock either behind or ahead of the ESX server time. Until the time is synchronized between the Sentinel appliance (guest) and the ESX server (host), Sentinel does not process events. As a result, a large number of events are queued up in the Collector Manager, which may eventually drop events once it reaches its threshold. To avoid this issue, Sentinel disables time synchronization by default in the open-vm-tools version available in Sentinel. (Bug 1099341)
Workaround: Disable time synchronization. For more information about disabling time synchronization, see Disabling Time Synchronization.
Issue: When FIPS 140-2 mode is enabled in Sentinel, using Windows authentication for Agent Manager causes synchronization with the Agent Manager database to fail. (Bug 814452)
Workaround: Use SQL authentication for Agent Manager.
Issue: The Sentinel High Availability installation in non-FIPS 140-2 mode completes successfully but displays the following error twice:
/opt/novell/sentinel/setup/configure.sh: line 1045: [: too many arguments
Workaround: The error is expected and you can safely ignore it. Although the installer displays the error, the Sentinel High Availability configuration works successfully in non-FIPS 140-2 mode.
Issue: In Internet Explorer 11, when you launch the dashboards:
Alert and Threat Hunting dashboard redirects to.
User Activity dashboard displays an error.
This issue occurs due to the URL length limitation in Internet Explorer 11. (Bug 1068418)
Workaround: Perform the following:
Launch Event Visualization dashboard.
Set the value of true.to
Issue: Restarting the Elasticsearch services in Sentinel fails with the unable to install syscall filter error after adding the Elasticsearch node to the cluster in RHEL 6. (Bug 1068600)
Workaround: Perform the following:
Log in to the Sentinel server as the novell user.
Open the /etc/opt/novell/sentinel/3rdparty/elasticsearch/elasticsearch.yml file.
Set the value of bootstrap.system_call_filter to false.
Restart the Elasticsearch services in Sentinel:
Issue: While using Keytool command, the following warning is displayed: The JKS keystore uses a proprietary format. It is recommended to migrate to PKCS12which is an industry standard format using "keytool -importkeystore -srckeystore /<sentinel_install_directory>/etc/opt/novell/sentinel/config/.webserverkeystore.jks -destkeystore /<sentinel_install_directory>/etc/opt/novell/sentinel/config/.webserverkeystore.jks -deststoretype pkcs12". (Bug 1086612)
Workaround: The warning is expected and you can safely ignore it. Although the warning is displayed, Keytool command works as expected.
Issue: In FIPS mode, when processing out-of-the-box threat Intelligence feeds from URLs, Sentinel displays the following error: Received fatal alert: protocol_version. This issue occurs because the out-of-the-box threat feeds now support only TLS 1.2, which does not work in FIPS mode. (Bug 1086631)
Workaround: Click http to https.> > . Edit each URL to change the protocol from
Issue: If Sentinel is integrated with NetIQ Advanced Authentication Framework MFA mode, you do not get logged out of Sentinel dashboards when you log out of Sentinel Main and vice versa due to an issue in the Advanced Authentication Framework. (Bug 1087856)
Workaround: Until a fix is available in the Advanced Authentication Framework, refresh the screen to view the login screen.
Issue: After installing or upgrading to Sentinel 8.2 in high availability mode, launching Sentinel Appliance Management Console displays an error. (Bug 1093574)
Workaround: After installing or upgrading to Sentinel 8.2, if the error is displayed after a failover, run the following command to restart Sentinel services:
systemctl restart vabase-datamodel.service vabase-jetty.service vabase.service
For information about NetIQ legal notices, trademarks, disclaimers, warranties, export and other use restrictions, U.S. Government restricted rights, patent policy, and FIPS compliance, see http://www.netiq.com/company/legal/.
Copyright © 2018 NetIQ Corporation. All Rights Reserved.