sentinelone data.md

SentinelOne

The Dropzone AI Platform integrates with SentinelOne, an endpoint cybersecurity platform that protects against various types of threats. Integrating SentinelOne with Dropzone allows Dropzone to automatically investigate security incidents in your SentinelOne environment.

Create a Service User and API Key

SentinelOne requires an API key from a Service User with Viewer Access to enable.

To obtain an API Key, do the following:

Settings

Create New Service User

Enter information

Assign roles to the new Account

Copy API Token

Enable SentinelOne

To enable the Data Source integration, you'll need the following information:

Dropzone Field Source
SentinelOne Hostname Your SentinelOne Hostname, e.g. usea1-123.sentinelone.net
API Token The API token value you copied earlier
SentinelOne XDR Hostname Your Singularity Data Lake Console hostname, e.g. xdr.us1.sentinelone.net

To enable the Data Source integration, do the following:

Integrations Dropdown

Click Available

The SentinelOne Tile

{% hint style="warning" %} Enabling the XDR API is optional, but provides crucial investigation data. {% endhint %}

The SentinelOne Data Source Configuration

If you have any errors or questions, engage your Dropzone AI support representative.