SentinelOneEventCollector
This integration fetches activities, threats, and alerts from SentinelOne.
- Category
- Analytics & SIEM
- Pack
- SentinelOne
Configuration parameters
- url — Server URL (e.g., https://usea1.sentinelone.net) (required)
- credentials — (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- isFetch — Fetch events
- event_type — Event types
- first_fetch — First fetch time
- fetch_limit — The maximum number of events per fetch should be between 1-1000
Commands (1)
- sentinelone-get-events — Gets events from SentinelOne.