How to Connect SentinelOne to SaaS Alerts
Before getting started
What SaaS Alerts requires:
Creating a SentinelOne API connection to SaaS Alerts requires the creation of a Service Account with viewer permissions within the SentinelOne dashboard. We suggest extending the user expiration date to a custom value of 3 years to prevent having to create a new service account and API Token.
The connection also requires your SentinelOne URL (the address you will log into to create the needed Service account).
Connecting SentinelOne to SaaS Alerts
- Create a new Organization or use an existing one and click the New Application button
- Select SentinelOne
- Enter your full SentinelOne instances URL and then the entire API Key that you generated with the Service Account created and click Finish
- After clicking Finish it may take up to 30 seconds or more to complete
PSA Support
Currently PSA ticket generation is supported by the App Wizard connections for all products as of May 2024.
Monitored Events
NOTE: the following list of events for the initial release;
- IAM Event - Authentication Success
- IAM Event - Authentication Failure
- IAM Event - MFA Authentication Failure
- IAM Event - User Logged Out
- IAM Event - New User Added
- IAM Event - Password Reset
- IAM Event - User Deleted
- IAM Event - Password Reset Initiated
- IAM Event - Account Locked
- IAM Event - Multi-Factor Authentication Enabled
- IAM Event - User Updated
Comments
0 comments
Article is closed for comments.