SentinelOneAlertsV2_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Tables Index


Attribute Value
Ingestion API Supported ✓ Yes

Contents

Schema (20 columns)

Source: Connector definition

Column Name Type Description
AlertId string Unique identifier of the unified alert.
AlertName string Human-readable alert name.
AnalystVerdict string Analyst verdict assigned to the alert.
Assets dynamic Assets associated with the alert.
AssigneeEmail string Email of the assignee.
AssigneeName string Full name of the assignee.
AttackSurfaces dynamic Attack surfaces associated with the alert.
Classification string Classification of the alert.
ConfidenceLevel string Confidence level of the detection.
CreatedAt datetime Time the alert was created.
DataSources dynamic Data sources associated with the alert.
DetectedAt datetime Time the alert was detected.
ExternalId string External identifier of the alert.
Product string Detection source product.
Severity string Severity of the alert.
Status string Current status of the alert.
StorylineId string Associated storyline identifier.
TimeGenerated datetime The timestamp (in UTC) when the log entry was generated.
UpdatedAt datetime Time the alert was last updated.
Vendor string Detection source vendor.

Schema References

Official Microsoft Learn documentation for field/column information:

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
[DEPRECATED] SentinelOne (using Azure Function)

Content Items Using This Table (22)

Analytic Rules (11)

In solution SentinelOne:

Analytic Rule Selection Criteria
Sentinel One - Admin login from new location
Sentinel One - Agent uninstalled from multiple hosts
Sentinel One - Alert from custom rule
Sentinel One - Blacklist hash deleted
Sentinel One - Exclusion added
Sentinel One - Multiple alerts on host
Sentinel One - New admin created
Sentinel One - Rule deleted
Sentinel One - Rule disabled
Sentinel One - Same custom rule triggered on different hosts
Sentinel One - User viewed agent's passphrase

Hunting Queries (10)

In solution SentinelOne:

Hunting Query Selection Criteria
Sentinel One - Agent not updated
Sentinel One - Agent status
Sentinel One - Alert triggers (files, processes, strings)
Sentinel One - Deleted rules
Sentinel One - Hosts not scanned recently
Sentinel One - New rules
Sentinel One - Scanned hosts
Sentinel One - Sources by alert count
Sentinel One - Uninstalled agents
Sentinel One - Users by alert count

Workbooks (1)

In solution SentinelOne:

Workbook Selection Criteria
SentinelOne

Parsers Using This Table (1)

Other Parsers (1)

Parser Solution Selection Criteria
SentinelOne SentinelOne

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Tables Index