The new SentinelOne App 5.1.1, doesn't show a rank field for the threats anymore under sourcetype="sentinelone:channel:threats"
How can we determine the rank of a threat now?
Good afternoon @guarisma ! Unfortunately, the "rank" field is deprecated in version 2.1 of the SentinelOne API. v5.1.X of the Splunk Integration uses v2.1 of the API, hence the discrepancy. Please direct further questions to SentinelOne support for follow up. Thank you!