All Apps and Add-ons

(Beginner) Splunk with Sentinelone

anglewwb35
Explorer

Hi i am new to splunk. As I am trying to integrate splunk with sentinelone, I found it frustrated to find which api key/token should I use... ( The SDL one or Management Console one). Also, I cannot find what the url and name should be under the Application Configuration page in Splunk. Hope you can help... Many thanks

Labels (2)
Tags (2)

lespinosas
Explorer

Hi, did you succed with this integration? I'm in the same situation...

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@anglewwb35- I'm not sure what kind of integration are you trying to do. But here is the references for Splunk API, which I hope will help you build the integration.

 

https://docs.splunk.com/Documentation/Splunk/9.2.1/RESTUM/RESTusing

https://docs.splunk.com/Documentation/Splunk/9.2.1/RESTREF/RESTprolog

kyle_kyle
Engager

they are probably talking about this   https://www.sentinelone.com/partners/featured-partner-splunk , but it that resource and what it links to haven't answered my questions about getting the SentinelOne Splunk app working 

 

Tags (2)
0 Karma
Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...