SentinelOne: Complete +

Prev Next

This is a Discovery Integration.

  • This integration collects 14 days of history by default upon first connection.


Collect Required Information from Vendor

IMPORTANT!

You must meet the following prerequisites before you can continue.

  • You must have the “Admin role.”

  • The Complete SKU (product option) is required for Deep Visibility access.

Generate Token

  1. Log in to your SentinelOne Management Console using one of the roles as defined above.

  2. Select the gear icon on the lower left.

  3. Go to AI SIEM.

  4. Go to API Keys > Log Access Keys.

  5. Select New Key.

  6. Copy/save the following field(s) for use when onboarding this Integration:

    • API Key Value

  7. Copy/save your DataLake URL for use when onboarding this Integration.

    • URL

      EXAMPLE:

      https://xdr.eu1.sentinelone.net

  8. Copy/save the AccountID (i.e., the scopeID in the URL):

    • AccountID

Onboard This Discovery Integration

  1. Go to SaaS Management > Applications.

  2. Select Add Integration.

  3. Select the Discovery Apps tab, then select the card with the vendor's name.

  4. From the API tab, enter the field(s) you copy/saved above.

  5. Select the Authorize button.

SUCCESS!

You will now be redirected to the Integrations page in Calero.com, where the data sync will continue in the background, and you can monitor progress.


SUGGESTION:

Access Help through your Calero.com instance if links between articles return errors or if there are fewer sections in the Help menu than expected. Doing so will ensure you see all Help articles.


Reference Information

API Endpoints

These are the API endpoints used to fetch both App Launch and URL data.

  • https://[domain].sentinelone.net/api-doc/api-details?category=long-running-query&api=launch-a-query

  • https://[domain].sentinelone.net/api-doc/api-details?category=long-running-query&api=poll-query

NOTE:

Replace [domain] with the domain.