Skip to main content

Overview

The SentinelOne integration enables ThreatAware to collect endpoint protection and threat detection data from your SentinelOne Management Console, providing visibility into endpoint security status and threat detection across your organisation.
Connection Method: API Setup Time: 15 minutes Access Required: SentinelOne Administrator account

Data collected

The SentinelOne integration provides:
  • Endpoint inventory and protection status
  • Threat detection and incident data
  • Remediation and quarantine information
  • System health and compliance status

Use cases

Endpoint Protection Monitoring

Monitor SentinelOne protection status across all managed endpoints

Threat Detection

Track detected threats and remediation actions

Incident Response

Monitor and respond to detected incidents

Compliance Verification

Verify all endpoints have active SentinelOne protection

Setup instructions

1

Log in to SentinelOne Management Console

  • Access your SentinelOne Management Console
  • Log in with an account that has administrator privileges
  • Note the Platform URL from your console’s address bar (e.g., https://euce1-110-nfr.sentinelone.net)
The Platform URL is critical for API authentication. Make sure to use the exact URL from your console.
2

Create Dedicated Admin Account

  • Navigate to Settings > Users or User Management in the SentinelOne console
  • Click Add User to create a new administrator account
  • Create an account specifically for API access (e.g., “threataware-api”)
  • Assign Admin permissions to the account
  • Set a strong, unique password for this account
  • Note the username and password for later use
This account will be used specifically for the ThreatAware integration. Keep the credentials secure and do not share them.
3

Generate API Token

  • Log in to the SentinelOne console with the newly created admin account
  • Navigate to My User > API Token or Account Settings > API Token
  • Click Generate to create a new API Token
  • Copy the API Token that is displayed
  • Note the token expiry date for your records
API tokens are displayed only once. Copy and securely store the token in your password manager before closing this screen.
4

Configure in ThreatAware

Complete the integration setup in ThreatAware:
  • Open ThreatAware and navigate to Settings > Integrations
  • Search for and select SentinelOne
  • Enter the required information:
    • Management Console URL: The Platform URL from your SentinelOne console (e.g., https://euce1-110-nfr.sentinelone.net)
    • API Token: The API token generated in the previous step
  • Click Authorize to establish the integration
5

Verify Connection

After connecting, verify the integration is working:
  • Check that the Integration Status shows as Active
  • Wait up to 5 minutes for the initial endpoint data sync
  • Verify endpoint protection data appears in ThreatAware
  • Confirm threat and incident data is being collected

Required credentials

Field Name: SentinelOne Management Console URL Type: String Description: The URL of your SentinelOne Management ConsoleThis is the base URL from your console’s address bar. Include the protocol (https).Format: https://region-platform.sentinelone.net Examples:
  • https://euce1-110-nfr.sentinelone.net
  • https://usea1-180-nfr.sentinelone.net
  • https://api.sentinelone.net
The console URL is displayed in your browser’s address bar when you log in. Copy it exactly as shown.
Field Name: SentinelOne API Token Type: Password (encrypted) Description: Authentication token for API access to SentinelOneGenerated in My User > API Token section of the SentinelOne console.
Store this credential securely in your organisation’s password manager. The token is only displayed once during generation.

Verification and testing

After setup, verify the integration is working correctly:
  1. Check Integration Status
    • Navigate to Settings > Integrations in ThreatAware
    • Confirm the SentinelOne integration shows Active status
    • Check the last sync timestamp
  2. Verify Data Collection
    • Wait up to 5 minutes for initial endpoint collection
    • Search for a known endpoint in ThreatAware
    • Verify SentinelOne protection status appears in endpoint details
  3. Test Queries
    • Create a test query to filter endpoints by SentinelOne protection status
    • Verify the results match your SentinelOne console data

Troubleshooting

Symptoms: Integration fails to authenticateSolutions:
  • Verify the API Token was copied correctly without extra spaces
  • Confirm the API Token has not expired (check the expiry date)
  • Check if the API Token was revoked or disabled in SentinelOne
  • Generate a new API Token if necessary
  • Ensure the API Token is for the correct user account
Symptoms: Integration fails due to URL issuesSolutions:
  • Verify the Management Console URL matches exactly what appears in your browser
  • Ensure the URL includes the protocol (https) and the region identifier
  • Remove any trailing slashes or paths from the URL
  • Test the URL in a browser to verify it’s accessible
  • Confirm you’re using the correct console URL for your region
Symptoms: Integration connects but no endpoint data appearsSolutions:
  • Verify the admin account has sufficient permissions in SentinelOne
  • Confirm the API Token is associated with an admin account
  • Check that the account has not been restricted to specific sites or groups
  • Review SentinelOne user permissions for the API account
  • Ensure the account is active and not disabled
Symptoms: Integration fails to connect or times outSolutions:
  • Verify the Management Console URL is accessible from your network
  • Test the URL in a browser to ensure it loads correctly
  • Check firewall rules allow outbound HTTPS (443) to SentinelOne
  • Confirm your internet connection is stable
  • Verify SentinelOne service is online and responsive
Symptoms: Integration shows active but no endpoint data appearsSolutions:
  • Verify you have endpoints enrolled in SentinelOne
  • Confirm the API Token has proper permissions to view endpoints
  • Wait up to 10 minutes for the initial data sync
  • Check SentinelOne console to verify data exists
  • Review ThreatAware integration logs for specific errors
  • Verify the admin account can access all required endpoints
Symptoms: Integration was working but stops collecting dataSolutions:
  • Check the API Token expiry date in your SentinelOne console
  • Generate a new API Token if the current one has expired
  • Update the token in ThreatAware with the new API Token
  • Set a reminder to rotate API tokens before expiry
  • Consider setting tokens to not expire if your policy allows

Additional resources

SentinelOne API Documentation

Official SentinelOne API documentation and reference materials

SentinelOne Support

SentinelOne support portal for technical assistance

Best practices

Credential Management
  • Create a dedicated admin account specifically for ThreatAware API access
  • Store the API Token securely in your organisation’s password manager
  • Rotate API tokens regularly (annually or per security policy)
  • Document the API Token generation date and expiry date
  • Monitor integration status to catch authentication failures early
Security Considerations
  • Only use the API Token for ThreatAware integration
  • Do not share API tokens with unauthorized users
  • Monitor SentinelOne audit logs for API account activity
  • Review endpoint protection status regularly
  • Keep integration status monitoring in place for continuity