All Apps and Add-ons

How can I integrate Splunk with Sentinel ONE?

fhirata1
Engager

Does anyone know how I can integrate sentinel one with splunk?

Is there any documentation I can follow or something?

 

Thank you.

Labels (1)
0 Karma

fhirata1
Engager

Hello Rich.

Thank you for your answer.

But I need to know how I do the integration with Splunk Cloud.

I follow this link:  file:///C:/Users/ze00230/Desktop/Nova%20pasta/Splunk_and_SentinelOne_Integration_v3.6-en.pdf

but it didn't work.

I created the user in the sentinel one panel, generated the api token, put it inside the Sentinel One app, but it is not working.

When I searchfor the word "sentinel" within Splunk it appears Internal logs, as shown in the image.

Captura de tela 2022-07-26 160616.png

What could I be doing wrong? Could you please help me ?

 

Thank you.

 

 

 

 

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The OP didn't mention Splunk Cloud, but the options in my first reply still apply.

Please explain what "it didn't work" means.  What results did you get and how do they not meet expectations?  What error messages do you get?

That "sentinel" appears in the internal logs indicates there may be errors.  What do the logs say?

---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

There are a few ways to onboard data into Splunk.

Install a universal forwarder on the server to send log files to Splunk
Have the server send syslog data to Splunk via a syslog server or Splunk Connect for Syslog
Use the server's API to extract data for indexing
Use Splunk DB Connect to pull data from the server's SQL database.

Look for a splunkbase add-on for the product.  It may explain how to integrate and should help extract fields.  There are a few such add-ons for Sentinel One.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...