Hi i am new to splunk. As I am trying to integrate splunk with sentinelone, I found it frustrated to find which api key/token should I use... ( The SDL one or Management Console one). Also, I cannot find what the url and name should be under the Application Configuration page in Splunk. Hope you can help... Many thanks
Hi, did you succed with this integration? I'm in the same situation...
@anglewwb35- I'm not sure what kind of integration are you trying to do. But here is the references for Splunk API, which I hope will help you build the integration.
https://docs.splunk.com/Documentation/Splunk/9.2.1/RESTUM/RESTusing
https://docs.splunk.com/Documentation/Splunk/9.2.1/RESTREF/RESTprolog
they are probably talking about this https://www.sentinelone.com/partners/featured-partner-splunk , but it that resource and what it links to haven't answered my questions about getting the SentinelOne Splunk app working