Overview

The SentinelOne integration polls the SentinelOne Management API to ingest:

  • Threat detections and mitigations
  • Alerts from Storyline Active Response (STAR) rules
  • Endpoint activity (process events, network connections)
  • Console audit events for user, role, and policy changes

Prerequisites

  • A SentinelOne management console URL (for example, https://usea1-partners.sentinelone.net).
  • A console user with permission to generate API tokens.

Step 1: Generate an API token

  1. Sign in to the SentinelOne Management Console.
  2. Click your user icon → My User.
  3. Open the Options tab and click Generate API Token (or Regenerate API Token).
  4. Copy the token value immediately. It is shown only once.

Tip: For least privilege, create a dedicated service user with a custom role that has only the View permissions for Threats, Alerts, Activities, and Audit Logs.


Step 2: Connect SentinelOne in Atatus

  1. In Atatus, go to Security → Cloud SIEM → Integrations.
  2. Locate the SentinelOne card and click Connect.
  3. Fill in the form:
Field Description Example
Console URL SentinelOne management console base URL. https://usea1-partners.sentinelone.net
API Token The token generated in Step 1. ••••••••
Poll Interval (minutes) How often to fetch new events. 5
Enabled Turn collection on. true
  1. Click Connect.

Verification

  • The SentinelOne card shows Configured.
  • Threats and audit events appear in Security → Cloud SIEM → Audit Logs → Events with source sentinelone.