The SentinelOne integration involves defining a Syslog Forwarder via the SentinelOne console.
The configuration parameters that need to be defined are:
The syslog forwarder config can be found under the Integrations section in SentinelOne management console:
In the syslog host section provide the public FQDN firehose.mycompany.com.
Define the TCP port provided by SOCFortress staff.
Select “Use TLS secure connection” and upload the following certificates:
NOTE: Before Testing conn ectivity, ensure that firewall rules in your on-prem firewall are in place (see next)
Finally, select RFC-5424 as the log format.
SentinelOne will forward alerts and events using their cloud endpoints as the source IP(s). Ensure that the following firewall rule is defined in your edge firewall:
NOTE: If not sure about what SRC IPs / Cloud EndPoints SentinelOne will use according to your region, ask SentinelOne's support.
The Notifications tab will allow selecting all the alerts and events that should be forwarded to the remote syslog/SIEM:
Was this article helpfu?
Thank you for voting
You are related to multiple companies. Please select the company you wish to login as.