SentinelOneAlerts_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Attribute Value
Ingestion API Supported ✓ Yes

Contents

Schema (9 columns)

Source: Connector definition

Column Name Type Description
AgentDetectionInfo string Detection information related to the agent.
AlertInfo string Details about the alert.
ContainerInfo string Information about the container.
KubernetesInfo string Kubernetes-related information.
RuleInfo string Information regarding the applied rule.
SourceParentProcessInfo string Information about the parent process of the source.
SourceProcessInfo string Information about the source process.
TargetProcessInfo string Details regarding the target process.
TimeGenerated datetime The timestamp (UTC) reflecting the time in which the event was generated.

Solutions (1)

This table is used by the following solutions:

Connectors (2)

This table is ingested by the following connectors:

Connector Selection Criteria
[DEPRECATED] SentinelOne (using Azure Function)
SentinelOne (via Codeless Connector Framework)

Content Items Using This Table (22)

Analytic Rules (11)

In solution SentinelOne:

Analytic Rule Selection Criteria
Sentinel One - Admin login from new location
Sentinel One - Agent uninstalled from multiple hosts
Sentinel One - Alert from custom rule
Sentinel One - Blacklist hash deleted
Sentinel One - Exclusion added
Sentinel One - Multiple alerts on host
Sentinel One - New admin created
Sentinel One - Rule deleted
Sentinel One - Rule disabled
Sentinel One - Same custom rule triggered on different hosts
Sentinel One - User viewed agent's passphrase

Hunting Queries (10)

In solution SentinelOne:

Hunting Query Selection Criteria
Sentinel One - Agent not updated
Sentinel One - Agent status
Sentinel One - Alert triggers (files, processes, strings)
Sentinel One - Deleted rules
Sentinel One - Hosts not scanned recently
Sentinel One - New rules
Sentinel One - Scanned hosts
Sentinel One - Sources by alert count
Sentinel One - Uninstalled agents
Sentinel One - Users by alert count

Workbooks (1)

In solution SentinelOne:

Workbook Selection Criteria
SentinelOne

Parsers Using This Table (1)

Other Parsers (1)

Parser Solution Selection Criteria
SentinelOne SentinelOne

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index