SentinelOneAgents_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Tables Index


Attribute Value
Supports Transformations ✓ Yes
Ingestion API Supported ✓ Yes
Lake-Only Ingestion ✓ Yes (source)

Contents

Schema (69 columns)

Source: Connector definition

Column Name Type Description
AccountId string Account id
AccountName string Account name
ActiveDirectory string Active directory
ActiveThreats real Active threats
AgentVersion string Agent version
AllowRemoteShell bool Allow remote shell
AppsVulnerabilityStatus string Apps vulnerability status
ComputerName string Computer name
ConsoleMigrationStatus string Console migration status
CoreCount real Core count
CpuCount real Cpu count
CpuId string Cpu id
CreatedAt datetime Created at
Domain string Domain
EncryptedApplications bool Encrypted applications
ExternalId string External id
ExternalIp string External ip
FullDiskScanLastUpdatedAt datetime Full disk scan last updated at
GroupId string Group id
GroupIp string Group ip
GroupName string Group name
GroupUpdatedAt datetime Group updated at
Id string Id
Infected bool Infected
InRemoteShellSession bool In remote shell session
InstallerType string Installer type
IsActive bool Is active
IsDecommissioned bool Is decommissioned
IsPendingUninstall bool Is pending uninstall
IsUninstalled bool Is uninstalled
IsUpToDate bool Is up to date
LastActiveDate datetime Last active date
LastIpToMgmt string Last ip to mgmt
LastLoggedInUserName string Last logged in user name
LicenseKey string License key
Locations string Locations
LocationType string Location type
MachineType string Machine type
MissingPermissions string Missing permissions
MitigationMode string Mitigation mode
MitigationModeSuspicious string Mitigation mode suspicious
ModelName string Model name
NetworkInterfaces string Network interfaces
NetworkQuarantineEnabled bool Network quarantine enabled
NetworkStatus string Network status
OperationalStateExpiration string Operational state expiration
OsArch string Os arch
OsName string Os name
OsRevision string Os revision
OsStartTime datetime Os start time
OsType string Os type
OsUsername string Os username
PolicyUpdatedAt datetime Policy updated at
RangerStatus string Ranger status
RangerVersion string Ranger version
RegisteredAt datetime Registered at
RemoteProfilingState string Remote profiling state
ScanAbortedAt datetime Scan aborted at
ScanFinishedAt datetime Scan finished at
ScanStartedAt datetime Scan started at
ScanStatus string Scan status
SiteId string Site id
SiteName string Site name
ThreatRebootRequired bool Threat reboot required
TimeGenerated datetime The timestamp (in UTC) when the log entry was generated.
TotalMemory real Total memory
UpdatedAt datetime Updated at
UserActionsNeeded string User actions needed
Uuid string Uuid

Schema References

Official Microsoft Learn documentation for field/column information:

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
[DEPRECATED] SentinelOne (using Azure Function)

Content Items Using This Table (22)

Analytic Rules (11)

In solution SentinelOne:

Analytic Rule Selection Criteria
Sentinel One - Admin login from new location
Sentinel One - Agent uninstalled from multiple hosts
Sentinel One - Alert from custom rule
Sentinel One - Blacklist hash deleted
Sentinel One - Exclusion added
Sentinel One - Multiple alerts on host
Sentinel One - New admin created
Sentinel One - Rule deleted
Sentinel One - Rule disabled
Sentinel One - Same custom rule triggered on different hosts
Sentinel One - User viewed agent's passphrase

Hunting Queries (10)

In solution SentinelOne:

Hunting Query Selection Criteria
Sentinel One - Agent not updated
Sentinel One - Agent status
Sentinel One - Alert triggers (files, processes, strings)
Sentinel One - Deleted rules
Sentinel One - Hosts not scanned recently
Sentinel One - New rules
Sentinel One - Scanned hosts
Sentinel One - Sources by alert count
Sentinel One - Uninstalled agents
Sentinel One - Users by alert count

Workbooks (1)

In solution SentinelOne:

Workbook Selection Criteria
SentinelOne

Parsers Using This Table (1)

Other Parsers (1)

Parser Solution Selection Criteria
SentinelOne SentinelOne

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Tables Index