Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Publisher | Microsoft Corporation |
| Support Tier | Microsoft |
| Support Link | https://support.microsoft.com |
| Categories | Security - Threat Protection |
| Version | 3.0.10 |
| Author | Microsoft - support@microsoft.com |
| First Published | 2024-11-26 |
| Last Updated | 2026-04-17 |
| Solution Folder | SentinelOne |
| Marketplace | Azure Marketplace · Rating: ★★★★★ 5.0/5 (1 ratings) · Popularity: 🔵 Medium (79%) |
The SentinelOne solution provides ability to bring SentinelOne events to your Microsoft Sentinel Workspace to inform and to examine potential security risks, analyze your team's use of collaboration, diagnose configuration problems and more.
Underlying Microsoft Technologies used:
This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:
a. Azure Monitor HTTP Data Collector API
This solution provides 3 data connector(s):
🔶 CLv1: This connector ingests into a table that uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g.
_s,_d,_b,_t,_g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.
This solution uses 13 table(s):
🔶 CLv1: This table uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g.
_s,_d,_b,_t,_g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.
This solution includes 23 content item(s):
| Content Type | Count |
|---|---|
| Analytic Rules | 11 |
| Hunting Queries | 10 |
| Workbooks | 1 |
| Parsers | 1 |
| Name | Tables Used |
|---|---|
| SentinelOne | SentinelOneActivities_CLSentinelOneAgents_CLSentinelOneAlertsV2_CLSentinelOneAlerts_CLSentinelOneGroups_CLSentinelOneThreats_CLSentinelOne_CL |
| Name | Description | Tables Used |
|---|---|---|
| SentinelOne | - | SentinelOne_CL (read) |
| Version | Date Modified (DD-MM-YYYY) | Change History |
|---|---|---|
| 3.1.0 | 01-07-2026 | Added new SentinelOne V2 (via Codeless Connector Framework) Data Connector (ingests alerts via the GraphQL API) |
| 3.0.10 | 03-06-2026 | Updated CCP Data Connector to support multiple instances (multi-connection) for MSSP scenarios |
| 3.0.9 | 14-04-2026 | Deprecate SentinelOne (using Azure Function) |
| 3.0.8 | 24-03-2026 | Rename CCF solution to SentinelOne (via Codeless Connector Framework) |
| 3.0.7 | 09-01-2026 | Updated broken URL and bumped the SentinelOne solution version |
| 3.0.6 | 10-02-2025 | Advancing CCP Data Connector from Public preview to Global Availability. |
| 3.0.5 | 20-01-2025 | Updated "Sentinel One - Agent uninstalled from multiple hosts" Analytic Rule with ActivityType |
| 3.0.4 | 15-01-2025 | Added older Function app Data Connector again to SOlution until final deprecation of Function app happens |
| 3.0.3 | 12-12-2024 | Added new CCP Data Connector and Updated Parser |
| 3.0.2 | 11-09-2024 | Updated the python runtime version to 3.11 in Data Connector Function App |
| 3.0.1 | 03-05-2024 | Repackaged for Parser issue fix |
| 3.0.0 | 28-07-2023 | Bug fixes in API version. |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊