<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sentinel One Integration with Splunk in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Sentinel-One-Integration-with-Splunk/m-p/711163#M21588</link>
    <description>&lt;P&gt;According to your screenshot, the inputs are "DISABLED". The checkmark follows typical Splunk inputs as "disabled == checked". Uncheck those inputs, and you should see data flow.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Mon, 10 Feb 2025 14:40:28 GMT</pubDate>
    <dc:creator>aplura_llc_supp</dc:creator>
    <dc:date>2025-02-10T14:40:28Z</dc:date>
    <item>
      <title>Sentinel One Integration with Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Sentinel-One-Integration-with-Splunk/m-p/711009#M21576</link>
      <description>&lt;P&gt;Hi. I am new to Splunk and SentinelOne. Here is what I've done so far:&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;I need to forward logs from SentinelOne to a single Splunk instance. Since it is a single instance, I installed the Splunk CIM Add-on and the SentinelOne App. (which is mentioned in the Installation of the app. &lt;/SPAN&gt;&lt;A href="https://splunkbase.splunk.com/app/5433" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://splunkbase.splunk.com/app/5433&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; )&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;In the SentinelOne App of the Splunk instance, I changed the search index to sentinelone in Application Configuration. I already created the index for testing purpose. In the API configuration, I added the url which is &lt;/SPAN&gt;&lt;A href="http://xxx-xxx-xxx.sentinelone.net" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;xxx-xxx-xxx.sentinelone.net&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; and the api token. It is generated by adding a new service user in SentinelOne and clicking generate API token. The scope is global. I am not sure if its the correct API token. &lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Moreover, I am not sure which channel I need to pick in SentinelOne inputs in Application Configuration(SentineOne App), such as Agents/Activities/Applications etc. How do I know which channel do i need to forward or i just add all channels?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="azer271_0-1739031342871.png" style="width: 553px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/34426i9B26F56373B7DF95/image-dimensions/553x255?v=v2" width="553" height="255" role="button" title="azer271_0-1739031342871.png" alt="azer271_0-1739031342871.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Clicking the application health overview, there is no data ingest of items. Using this SPL index=_internal sourcetype="sentinelone*" sourcetype="sentinelone:modularinput" does not show any action=saving_checkpoint, which means no data.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="azer271_1-1739031391390.png" style="width: 763px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/34427iC452B5F0CF058A73/image-dimensions/763x186?v=v2" width="763" height="186" role="button" title="azer271_1-1739031391390.png" alt="azer271_1-1739031391390.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Any help/documentation for the setup would be helpful. I would like to know the reason for no data and how to fix it. Thank you.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Feb 2025 16:23:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Sentinel-One-Integration-with-Splunk/m-p/711009#M21576</guid>
      <dc:creator>azer271</dc:creator>
      <dc:date>2025-02-08T16:23:19Z</dc:date>
    </item>
    <item>
      <title>Re: Sentinel One Integration with Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Sentinel-One-Integration-with-Splunk/m-p/711013#M21577</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/264981"&gt;@azer271&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;To verify, you can test the API connection by using &lt;STRONG&gt;Postman&lt;/STRONG&gt; or &lt;SPAN class=""&gt;curl&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;curl -X GET "&lt;A href="https://xxx-xxx-xxx.sentinelone.net/web/api/v2.1/info" target="_blank" rel="noopener"&gt;https://xxx-xxx-xxx.sentinelone.net/web/api/v2.1/info&lt;/A&gt;" -H "Authorization: APIToken"&lt;/P&gt;&lt;P class=""&gt;If you get a successful response, the API token is valid.&lt;/P&gt;&lt;P class=""&gt;If logs are missing, check &lt;STRONG&gt;API permissions&lt;/STRONG&gt;, &amp;nbsp;and any firewall restrictions.&lt;/P&gt;</description>
      <pubDate>Sun, 09 Feb 2025 05:41:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Sentinel-One-Integration-with-Splunk/m-p/711013#M21577</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-02-09T05:41:12Z</dc:date>
    </item>
    <item>
      <title>Re: Sentinel One Integration with Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Sentinel-One-Integration-with-Splunk/m-p/711014#M21578</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/264981"&gt;@azer271&lt;/a&gt;&amp;nbsp;Check the internal logs:&lt;/P&gt;&lt;PRE&gt;index=_internal *sentinelone*&lt;/PRE&gt;</description>
      <pubDate>Sun, 09 Feb 2025 05:44:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Sentinel-One-Integration-with-Splunk/m-p/711014#M21578</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-02-09T05:44:56Z</dc:date>
    </item>
    <item>
      <title>Re: Sentinel One Integration with Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Sentinel-One-Integration-with-Splunk/m-p/711163#M21588</link>
      <description>&lt;P&gt;According to your screenshot, the inputs are "DISABLED". The checkmark follows typical Splunk inputs as "disabled == checked". Uncheck those inputs, and you should see data flow.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2025 14:40:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Sentinel-One-Integration-with-Splunk/m-p/711163#M21588</guid>
      <dc:creator>aplura_llc_supp</dc:creator>
      <dc:date>2025-02-10T14:40:28Z</dc:date>
    </item>
    <item>
      <title>Re: Sentinel One Integration with Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Sentinel-One-Integration-with-Splunk/m-p/711277#M21602</link>
      <description>&lt;P&gt;The inputs are unchecked now. disabled = 0 in local/inputs.conf as well. 443/tcp is allowed in firewall.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="azer271_2-1739285589369.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/34453i4948C7CE6F0B4E10/image-size/medium?v=v2&amp;amp;px=400" role="button" title="azer271_2-1739285589369.png" alt="azer271_2-1739285589369.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="azer271_0-1739285388274.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/34451i865BB1C19584A9A9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="azer271_0-1739285388274.png" alt="azer271_0-1739285388274.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;There is still no data. Is there anything I am missing? Thank you everyone for your help!&lt;/P&gt;&lt;P&gt;API Token Post Request:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="azer271_3-1739285753628.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/34454i94403663C1D3747B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="azer271_3-1739285753628.png" alt="azer271_3-1739285753628.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;internal log:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="azer271_1-1739285466722.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/34452i1AE2CDA0E4F7967E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="azer271_1-1739285466722.png" alt="azer271_1-1739285466722.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 14:56:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Sentinel-One-Integration-with-Splunk/m-p/711277#M21602</guid>
      <dc:creator>azer271</dc:creator>
      <dc:date>2025-02-11T14:56:31Z</dc:date>
    </item>
    <item>
      <title>Re: Sentinel One Integration with Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Sentinel-One-Integration-with-Splunk/m-p/742724#M21982</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/264981"&gt;@azer271&lt;/a&gt;,&amp;nbsp;&lt;BR /&gt;have you solved the issue?&lt;BR /&gt;&lt;BR /&gt;I'm also having the same.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 15:00:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Sentinel-One-Integration-with-Splunk/m-p/742724#M21982</guid>
      <dc:creator>molla</dc:creator>
      <dc:date>2025-03-26T15:00:48Z</dc:date>
    </item>
    <item>
      <title>Re: Sentinel One Integration with Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Sentinel-One-Integration-with-Splunk/m-p/742930#M22001</link>
      <description>&lt;P&gt;I solved the issue by unchecking the inputs in the app, since they are disabled by default and making sure the API permissions in Sentinel One. In my case, i just create a new service user in Sentinel One and use the api generated from the service user. The user has the scope of access to the site.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Mar 2025 12:56:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Sentinel-One-Integration-with-Splunk/m-p/742930#M22001</guid>
      <dc:creator>azer271</dc:creator>
      <dc:date>2025-03-28T12:56:51Z</dc:date>
    </item>
  </channel>
</rss>

