# SentinelOne Integration

**URL:** <https://discuss.elastic.co/t/sentinelone-integration/310378>\
**Category:** Elasticsearch\
**Tags:** elastic-agent, integrations\
**Created:** [July 22, 2022, 9:49am UTC](https://discuss.elastic.co/t/sentinelone-integration/310378 "2022-07-22T09:49:05Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Medel](https://avatars.discourse-cdn.com/v4/letter/m/f07891/32.png) [@Medel](https://discuss.elastic.co/u/Medel)\
**Post date:** [July 22, 2022, 9:49am UTC](https://discuss.elastic.co/t/sentinelone-integration/310378/1 "2022-07-22T09:49:05Z")

</div>

Hello ,  
I'm trying to integrate SentinelOne API to Elastic for the purpose of collecting logs but unfortunatly i can't find any tutorial or information on how to use the API token generated from the used and integrate it to Elastic,  
Cordially,

---

<div class="post-metadata">

**Author:** ![jamie.hynds](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamie.hynds/32/84205_2.png) [@jamie.hynds](https://discuss.elastic.co/u/jamie.hynds)\
**Post date:** [July 22, 2022, 10:06am UTC](https://discuss.elastic.co/t/sentinelone-integration/310378/2 "2022-07-22T10:06:19Z")

</div>

Hi @Medel - welcome to the Discuss community!

Within Kibana, if you go to Management -\> Integrations, you should see the SentinelOne integration there. Once you go to that integration and click 'Add SentintelOne' it will take you to the integration configuration, where you can enter your S1 console URL and API key.

 ![Screenshot 2022-07-22 at 11.03.33](https://us1.discourse-cdn.com/elastic/original/3X/5/d/5d901c31b1c991e56c1e9d18efbb0ecd470c474f.png)

You'll then need to assign the integration to an Elastic Agent to collect the events and ship to Elastic. For more information on Elastic Agent, please see [here](https://www.elastic.co/guide/en/fleet/current/index.html).

---

<div class="post-metadata">

**Author:** ![Medel](https://avatars.discourse-cdn.com/v4/letter/m/f07891/32.png) [@Medel](https://discuss.elastic.co/u/Medel)\
**Post date:** [July 22, 2022, 11:00am UTC](https://discuss.elastic.co/t/sentinelone-integration/310378/3 "2022-07-22T11:00:53Z")

</div>

Thank you so much, Jamie, for your time !  
I appreciate it a lot .  
Do you have any idea about the ways to parse the alerts coming from sentinelOne , In order to display them in a more intuitive from than the default display:

 ![Screenshot 2022-07-22 120000](https://us1.discourse-cdn.com/elastic/original/3X/f/f/ff364c5329d3244923d4219224fd6e4a4bebcc5e.png)

Thank you very much again

---

<div class="post-metadata">

**Author:** ![jamie.hynds](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamie.hynds/32/84205_2.png) [@jamie.hynds](https://discuss.elastic.co/u/jamie.hynds)\
**Post date:** [July 22, 2022, 11:20am UTC](https://discuss.elastic.co/t/sentinelone-integration/310378/4 "2022-07-22T11:20:21Z")

</div>

The example within the documentation is just the raw JSON events, but once you enable the integration and start ingesting alerts, you can interact with them within [Timeline](https://www.elastic.co/guide/en/security/current/timelines-ui.html) and also via the dashboards included with the integration.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 19, 2022, 11:21am UTC](https://discuss.elastic.co/t/sentinelone-integration/310378/5 "2022-08-19T11:21:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
