All integrations

Endpoint (EDR)

SentinelOne

One more source in the Data Fusion layer.

Connect SentinelOne to make supported endpoint (edr) data available to the Data Fusion layer. Ingestion, live query, and response support depend on the connector.

WHY CONNECT IT

Put This Source
In the Full Story.

01

Bring supported endpoint (edr) events into the same investigation.

02

Correlate this source with connected identity, endpoint, cloud, network, and application context.

03

Store the stream in Port0 or query it in place, whichever fits the data path.

HOW DATA MOVES

Connect. Choose.
Use the Context.

SentinelOneConnected source
Store or queryIn Port0, or in place
Data FusionContext for workflows

NEXT STEP

Connect SentinelOne.
See It in Context.

See how this source fits your environment before you deploy.

Book a demo