sentinelone
Overview
This documentation outlines the configuration process for SentinelOne to transfer data to AlphaSOC for analysis. Through this integration, the endpoint telemetry ingested by SentinelOne can be used for security monitoring and threat detection.
To enable data log transfers:
- Enable Deep Visibility in your SentinelOne console.
- Export logs by creating a Cloud Funnel to Amazon Simple Storage Service (S3) or a Google Cloud Storage (GCS) bucket.
- Follow AlphaSOC's guide for Collecting data through Amazon S3 or Collecting data through GCS.
After completing the setup and transferring telemetry, the data can be processed by AlphaSOC for analysis.
Enabling Deep Visibility
- Log into your SentinelOne console.
- Open Policy tab.
- Go to Deep Visibility configuration.
- Click the toggle near Enable Deep Visibility and select chosen data types.
- Click Save.
Exporting Logs to Amazon S3
note
This part requires an existing Amazon S3 bucket.
- Open SentinelOne Deep Visibility.
- Go to Configure > Policy & Settings, and click Cloud Funnel in the Singularity Data Lake section.
- Select AWS as your cloud provider.
- Enter the name of your S3 bucket in the S3 Bucket Name field.
- Turn on Telemetry Streaming by selecting Enable.
- In the Query Filters box, create a query to specify which agents should send data to the S3 bucket.
- Click Validate to validate your query.
- Ensure that all fields are selected under Fields to Include.
- Click Save.
Exporting Logs to GCS
Follow Google Cloud's guide for collecting SentinelOne Deep Visibility logs.