Overview
The SentinelOne integration enables ThreatAware to collect endpoint protection and threat detection data from your SentinelOne Management Console, providing visibility into endpoint security status and threat detection across your organisation.Connection Method: API
Setup Time: 15 minutes
Access Required: SentinelOne Administrator account
Data collected
The SentinelOne integration provides:- Endpoint inventory and protection status
- Threat detection and incident data
- Remediation and quarantine information
- System health and compliance status
Use cases
Endpoint Protection Monitoring
Monitor SentinelOne protection status across all managed endpoints
Threat Detection
Track detected threats and remediation actions
Incident Response
Monitor and respond to detected incidents
Compliance Verification
Verify all endpoints have active SentinelOne protection
Setup instructions
1
Log in to SentinelOne Management Console
- Access your SentinelOne Management Console
- Log in with an account that has administrator privileges
- Note the Platform URL from your console’s address bar (e.g.,
https://euce1-110-nfr.sentinelone.net)
2
Create Dedicated Admin Account
- Navigate to Settings > Users or User Management in the SentinelOne console
- Click Add User to create a new administrator account
- Create an account specifically for API access (e.g., “threataware-api”)
- Assign Admin permissions to the account
- Set a strong, unique password for this account
- Note the username and password for later use
3
Generate API Token
- Log in to the SentinelOne console with the newly created admin account
- Navigate to My User > API Token or Account Settings > API Token
- Click Generate to create a new API Token
- Copy the API Token that is displayed
- Note the token expiry date for your records
4
Configure in ThreatAware
Complete the integration setup in ThreatAware:
- Open ThreatAware and navigate to Settings > Integrations
- Search for and select SentinelOne
- Enter the required information:
- Management Console URL: The Platform URL from your SentinelOne console (e.g.,
https://euce1-110-nfr.sentinelone.net) - API Token: The API token generated in the previous step
- Management Console URL: The Platform URL from your SentinelOne console (e.g.,
- Click Authorize to establish the integration
5
Verify Connection
After connecting, verify the integration is working:
- Check that the Integration Status shows as Active
- Wait up to 5 minutes for the initial endpoint data sync
- Verify endpoint protection data appears in ThreatAware
- Confirm threat and incident data is being collected
Required credentials
Management Console URL
Management Console URL
Field Name: SentinelOne Management Console URL
Type: String
Description: The URL of your SentinelOne Management ConsoleThis is the base URL from your console’s address bar. Include the protocol (https).Format:
https://region-platform.sentinelone.net
Examples:https://euce1-110-nfr.sentinelone.nethttps://usea1-180-nfr.sentinelone.nethttps://api.sentinelone.net
API Token
API Token
Field Name: SentinelOne API Token
Type: Password (encrypted)
Description: Authentication token for API access to SentinelOneGenerated in My User > API Token section of the SentinelOne console.
Verification and testing
After setup, verify the integration is working correctly:-
Check Integration Status
- Navigate to Settings > Integrations in ThreatAware
- Confirm the SentinelOne integration shows Active status
- Check the last sync timestamp
-
Verify Data Collection
- Wait up to 5 minutes for initial endpoint collection
- Search for a known endpoint in ThreatAware
- Verify SentinelOne protection status appears in endpoint details
-
Test Queries
- Create a test query to filter endpoints by SentinelOne protection status
- Verify the results match your SentinelOne console data
Troubleshooting
Invalid Token Error
Invalid Token Error
Symptoms: Integration fails to authenticateSolutions:
- Verify the API Token was copied correctly without extra spaces
- Confirm the API Token has not expired (check the expiry date)
- Check if the API Token was revoked or disabled in SentinelOne
- Generate a new API Token if necessary
- Ensure the API Token is for the correct user account
Incorrect Console URL
Incorrect Console URL
Symptoms: Integration fails due to URL issuesSolutions:
- Verify the Management Console URL matches exactly what appears in your browser
- Ensure the URL includes the protocol (https) and the region identifier
- Remove any trailing slashes or paths from the URL
- Test the URL in a browser to verify it’s accessible
- Confirm you’re using the correct console URL for your region
Permission Issues
Permission Issues
Symptoms: Integration connects but no endpoint data appearsSolutions:
- Verify the admin account has sufficient permissions in SentinelOne
- Confirm the API Token is associated with an admin account
- Check that the account has not been restricted to specific sites or groups
- Review SentinelOne user permissions for the API account
- Ensure the account is active and not disabled
Connection Timeout
Connection Timeout
Symptoms: Integration fails to connect or times outSolutions:
- Verify the Management Console URL is accessible from your network
- Test the URL in a browser to ensure it loads correctly
- Check firewall rules allow outbound HTTPS (443) to SentinelOne
- Confirm your internet connection is stable
- Verify SentinelOne service is online and responsive
No Data After 5 Minutes
No Data After 5 Minutes
Symptoms: Integration shows active but no endpoint data appearsSolutions:
- Verify you have endpoints enrolled in SentinelOne
- Confirm the API Token has proper permissions to view endpoints
- Wait up to 10 minutes for the initial data sync
- Check SentinelOne console to verify data exists
- Review ThreatAware integration logs for specific errors
- Verify the admin account can access all required endpoints
API Token Expiration
API Token Expiration
Symptoms: Integration was working but stops collecting dataSolutions:
- Check the API Token expiry date in your SentinelOne console
- Generate a new API Token if the current one has expired
- Update the token in ThreatAware with the new API Token
- Set a reminder to rotate API tokens before expiry
- Consider setting tokens to not expire if your policy allows
Additional resources
SentinelOne API Documentation
Official SentinelOne API documentation and reference materials
SentinelOne Support
SentinelOne support portal for technical assistance