Integration: Kaseya SIEM and SentinelOne

Overview

The SentinelOne integration connects your SentinelOne environment to Kaseya SIEM to make endpoint threat data available for monitoring and investigation within Kaseya SIEM.

Prerequisites

  • Active SentinelOne account

  • Access to the SentinelOne Cloud console

  • Permissions to create service users and API tokens

  • SentinelOne API token

  • SentinelOne API domain URL

Use case

You are using SentinelOne to monitor endpoint activity and want those threats to be visible in Kaseya SIEM. After configuring the integration, SentinelOne threat data is available in Kaseya SIEM, where it can be reviewed alongside other data sources and included in investigation workflows.

How to...