setup

SentinelOne

Purpose

Imports SentinelOne endpoint security data (accounts, agents, applications, and findings) so endpoint telemetry can be correlated with cloud and identity data.

tip

Secret fields below accept either an AWS Secrets Manager ARN or a value pasted directly into SubImage's managed vault. See Secrets for details.

Required Fields

Field Secret? Description
sentinelone_api_url No SentinelOne management API base URL
sentinelone_api_token Yes SentinelOne API token
sentinelone_account_ids No Account IDs to scope the sync (leave empty for all)

Setup Steps

  1. In SentinelOne, open Settings → Users → Service Users.
  2. Actions → Create New Service User. Enter a name and expiration date; click Next.
  3. Choose the site or account the service user should access; click Create.
  4. Copy the API token — SentinelOne only displays it once.
  5. Note your API base URL (e.g. https://usea1-partners.sentinelone.net).
  6. In SubImage, fill in:
    • sentinelone_api_url — the API base URL
    • sentinelone_api_token — the token (or its AWS Secret ARN)
    • sentinelone_account_ids — optional; one account ID per entry
  7. Save the module and run a manual sync to validate.