All Apps and Add-ons

SentinelOne App: Why we don't have eventtype=sentinelone_threats?

Agirbal
New Member

Hi,

I'm new to splunk. We use SplunkCloud 8.2.

I install the SentinelOne App for splunk v5.1.3.

Many dashboard are working fine, but not all.

At "YOURS".splunkcloud.com/en-US/app/sentinelone_app_for_splunk/s1_threats_overview, there is a Panel for "Active Threats (raw)". The associate search is :

 

eventtype=sentinelone_threats (host="*") (siteName="*") NOT threatInfo.incidentStatus="resolved" AND threatInfo.mitigationStatus="active" 

 

Seems "sentinelone_threats" eventtype doesn't exist.

I search over all index (index=*), don't find this eventtype.

My SentinelOne seems weel configured, API connection is OK, I configure all channels, but I don't have this eventtype.

Any idea?

Thanks

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...