TEAM: Huntress Managed Security Information and Event Management (SIEM)
PRODUCT: API Log Source
ENVIRONMENT: Sentinel One
SUMMARY: Configuration Guide for Sentinel One Activity Ingestion
Vendor Information
Vendor | Sentinel One |
---|---|
Supported Model Name/Number | |
Supported License Version(s) | |
Collection Method | API / Syslog |
Provider Name | Syslog-SentinelOne |
Additional Information |
Device Configuration Checklist
Create a Role for the Service User
- In the SentinelOne management console, go to
Settings
, selectUSERS
, and then selectRoles
. - Select the built-in
Viewer
role, then chooseDuplicate Role
in the Actions drop down menu

- Provide a name for the new user role (e.g. Huntress SIEM Integration) then select
NEXT
. - Navigate to the following sections and add the noted permissions:
Console Integrations
(Edit
,Create
)Notification Settings
(Edit
,Create
)
Create Service User
- In the SentinelOne management console, go to
Settings
, selectUSERS
, and then selectService Users
. - Create a new
Service User
by specifying a name and an expiration date, then clickNext
.
The API token you generate is time-limited. To generate a new token (and invalidate the old one), you may need to copy the Service User. Please refer to the SentinelOne documentation for more information on how to perform these steps.
- On the Scope of Access screen, you will want to select
Account
in the Access Level section. This allows you to use a single token to map all SentinelOne Sites within Huntress. Otherwise, you will need to create multiple integrations and track the expiration of each token separately. - Click
Create User
to obtain the API token. - Securely copy the API token for the service user, then choose
Close
.
Create Huntress Integration
- Navigate to Huntress SIEM -> Source Management -> SentinelOne
- Select the green +Add button to create a new Sentinel One configuration.
Enter the details of the configuration as needed, including the API key obtained in the first two steps. Save the configuration. The Default Organization will be where logs that aren't endpoint or site-specific will be stored.
After saving, you'll be directed to the Configure page where you will need to map the organizations between SentinelOne and Huntress. For each SentinelOne Site, select a Huntress equivalent organization from the dropdown. Any data received from unmapped organizations will be discarded.
The License Count column will determine the number of data sources billed per mapped organization.
Any data received from SentinelOne for a Site that is not mapped will be discarded.
Once the organizations have been mapped, the SentinelOne configuration page will show the mapped log sources.