Skip to main content

How to Integrate SentinelOne

In this guide, we'll run through how to integrate SentinelOne with the Defense.com SIEM platform.

Kara Crimson avatar
Written by Kara Crimson
Updated over a week ago

The SentinelOne integration is available on our Advanced and Enterprise packages.

Before you get started

This integration requires us to configure a collector on the edge of our network to receive your log data directly from SentinelOne. Before you get started, please reach out to our Technical Support team and make them aware that you're planning on setting up this integration.

They will then deploy the collector required for this and provide you with the port and certificates mentioned later in this guide. The certificates will come in an attachment on the support ticket containing 3 files: ca.crt; client.crt and client.key.

Configuring SentinelOne

  1. Open the SentinelOne Admin Console to configure SentinelOne to send logs to your Syslog server.

  2. Select your site.

  3. In the left side menu, click the slider icon [⊢] to open the Settings menu.

  4. Open the INTEGRATIONS tab, and fill in the details:

    1. Under Types, select SYSLOG.

      Toggle the button to enable SYSLOG.

    2. Host - Enter the syslog host address and port.

      Host: Edge-collector.defense.com

      Port: This will be provided by the Defense.com technical support team via the support ticket.

  5. Check the Use TLS secure connection box and upload the three certs from the zip file provided via the ticket.

  6. Formatting - Select CEF2.

  7. Save your changes.

Once you have completed the configuration steps, please let us know via the ticket so we can confirm that SentinelOne is logging.

And that's it! You've successfully integrated SentinelOne πŸŽ‰

Did this answer your question?