SentinelOneActivities_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Tables Index


Attribute Value
Supports Transformations ✓ Yes
Ingestion API Supported ✓ Yes
Lake-Only Ingestion ✓ Yes (source)

Contents

Schema (23 columns)

Source: Connector definition

Column Name Type Description
AccountId string Account id
AccountName string Account name
ActivityType real Activity type
ActivityUuid string Activity uuid
AgentId string Agent id
AgentUpdatedVersion string Agent updated version
Comments string Comments
CreatedAt datetime Created at
Data string Data
Description string Description
GroupId string Group id
GroupName string Group name
Hash string Hash
Id string Id
OsFamily string Os family
PrimaryDescription string Primary description
SecondaryDescription string Secondary description
SiteId string Site id
SiteName string Site name
ThreatId string Threat id
TimeGenerated datetime The timestamp (in UTC) when the log entry was generated.
UpdatedAt datetime Updated at
UserId string User id

Schema References

Official Microsoft Learn documentation for field/column information:

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
[DEPRECATED] SentinelOne (using Azure Function)

Content Items Using This Table (22)

Analytic Rules (11)

In solution SentinelOne:

Analytic Rule Selection Criteria
Sentinel One - Admin login from new location
Sentinel One - Agent uninstalled from multiple hosts
Sentinel One - Alert from custom rule
Sentinel One - Blacklist hash deleted
Sentinel One - Exclusion added
Sentinel One - Multiple alerts on host
Sentinel One - New admin created
Sentinel One - Rule deleted
Sentinel One - Rule disabled
Sentinel One - Same custom rule triggered on different hosts
Sentinel One - User viewed agent's passphrase

Hunting Queries (10)

In solution SentinelOne:

Hunting Query Selection Criteria
Sentinel One - Agent not updated
Sentinel One - Agent status
Sentinel One - Alert triggers (files, processes, strings)
Sentinel One - Deleted rules
Sentinel One - Hosts not scanned recently
Sentinel One - New rules
Sentinel One - Scanned hosts
Sentinel One - Sources by alert count
Sentinel One - Uninstalled agents
Sentinel One - Users by alert count

Workbooks (1)

In solution SentinelOne:

Workbook Selection Criteria
SentinelOne

Parsers Using This Table (1)

Other Parsers (1)

Parser Solution Selection Criteria
SentinelOne SentinelOne

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Tables Index