Getting started with SentinelOne↑
AQtive Guard can ingest SentinelOne endpoint data, including installed applications and IT inventory details, to enable centralized IT management and enhance security posture.
SentinelOne requirements↑
- The SentinelOne URL you will connect to.
- A SentinelOne API token (requires user creation).
Configure the SentinelOne integration↑
There are two main steps to configure the SentinelOne integration:
- In SentinelOne: Create a user account and generate an API token.
- In AQtive Guard: Configure the SentinelOne data source.
Create a user↑
In SentinelOne, follow these steps to create a user and generate an API token. For more information, refer to Generating an API token in the SentinelOne user documentation.
- Sign in to the SentinelOne Management Console with Admin user credentials.
- In the Management Console, select Settings.
- In the Settings view, select Users, then Service Users.
- Select the Actions dropdown, then Create New Service User.
- Enter the information for the new service user.
- In Role, select Admin.
- Select Save.
Log in to the SentinelOne Management Console with the credentials of the new user you just created to complete the following steps.
- Navigate to Settings, then Users.
- Select the newly added service user.
- Select Options, then Generate API token.
- Copy or download this API Token.
Note
The API token will not be displayed again for security reasons.
Configure the SentinelOne data source↑
Log in to AQtive Guard to complete the following steps.
- Select Data sources from the main menu, then select Configure in the SentinelOne panel.
- Enter the following information into the designated fields:
- Instance URL - the location of the SentinelOne API.
- API Token - the API token you generated in SentinelOne.
- (Optional) Select Test Connection to check the connection to the SentinelOne API.
- Select Submit to update the settings.
Note
Selecting Submit performs the same check as the Test connection button, in addition to verifying the API token is valid.
Use↑
Once the integration is configured, you can trigger a SentinelOne inventory ingestion.
Note
If the SentinelOne settings aren’t configured, the ingestion option will be disabled.
To ingest inventory data from SentinelOne:
- Select Data sources from the main menu, then select Details in the SentinelOne panel.
-
Select: Start IT Inventory ingestion to trigger the ingestion of data into AQtive Guard.
You’ll see a notification confirming that the data ingestion has started.
View SentinelOne data↑
Once the ingestion is complete, any relevant data will begin populating. To find it:
- From IT Assets, select Hosts or Apps.
Look for the S1 tag in the Data sources column.
Unlink the SentinelOne integration↑
Unlink the SentinelOne integration only if your organization needs to reconfigure or stop data sharing with SentinelOne.
To unlink the SentinelOne configuration:
- Select Data sources from the main menu, then select Details in the SentinelOne panel.
- Select Unlink.
- Select Confirm and unlink SentinelOne.