Overview
The SentinelOne integration polls the SentinelOne Management API to ingest:
- Threat detections and mitigations
- Alerts from Storyline Active Response (STAR) rules
- Endpoint activity (process events, network connections)
- Console audit events for user, role, and policy changes
Prerequisites
- A SentinelOne management console URL (for example,
https://usea1-partners.sentinelone.net). - A console user with permission to generate API tokens.
Step 1: Generate an API token
- Sign in to the SentinelOne Management Console.
- Click your user icon → My User.
- Open the Options tab and click Generate API Token (or Regenerate API Token).
- Copy the token value immediately. It is shown only once.
Tip: For least privilege, create a dedicated service user with a custom role that has only the View permissions for Threats, Alerts, Activities, and Audit Logs.
Step 2: Connect SentinelOne in Atatus
- In Atatus, go to Security → Cloud SIEM → Integrations.
- Locate the SentinelOne card and click Connect.
- Fill in the form:
| Field | Description | Example |
|---|---|---|
| Console URL | SentinelOne management console base URL. | https://usea1-partners.sentinelone.net |
| API Token | The token generated in Step 1. | •••••••• |
| Poll Interval (minutes) | How often to fetch new events. | 5 |
| Enabled | Turn collection on. | true |
- Click Connect.
Verification
- The SentinelOne card shows Configured.
- Threats and audit events appear in Security → Cloud SIEM → Audit Logs → Events with source
sentinelone.
+1-415-800-4104