SentinelOne
runZero imports SentinelOne data through the SentinelOne API to sync and enrich your asset inventory, import the software installed on assets, and import the vulnerabilities affecting that software. With SentinelOne data in runZero, vulnerable endpoints and endpoints missing required software are easier to find.
Getting started
To set up the SentinelOne integration, you’ll need to:
- Configure SentinelOne to allow API access to runZero.
- Add the SentinelOne API key and SentinelOne base API URL in runZero.
- Choose whether to run the integration as a scan probe or connector task.
- Activate the SentinelOne integration to sync your data with runZero.
Requirements
Before you set up the SentinelOne integration:
- Make sure you have access to the SentinelOne admin portal.
Step 1: Configure SentinelOne to allow API access to runZero
- Sign in to SentinelOne with the account you use for the runZero integration.
- Go to User > My User.
- Generate the API token, then download or copy it. This API key expires every six months and must be regenerated.
Step 2: Add the SentinelOne credential to runZero
- Go to the Credentials page in runZero. Provide a name for the credentials, like
SentinelOne. - Choose SentinelOne API key from the list of credential types.
- Fill in these fields:
- SentinelOne API URL - Your organization-specific base URL, which depends on your account type and looks like
organization.sentinelone.net. - SentinelOne API key - The API key from User > My User in your SentinelOne portal, where you can generate, regenerate, or revoke a key.
- SentinelOne API URL - Your organization-specific base URL, which depends on your account type and looks like
- To let other organizations use this credential, select the Make this a global credential option. Otherwise, you can grant access per organization.
- Save the credential.
Step 3: Choose how to configure the SentinelOne integration
You can run the SentinelOne integration as either a scan probe or a connector task. A scan probe gathers integration data during scan tasks. A connector task runs on its own, from the cloud or from one of your Explorers, and performs only the integration sync.
Step 4: Set up and activate the SentinelOne integration to sync data
After you add your SentinelOne credential, set up a connector task or scan probe to sync your data.
Step 4a: Configure the SentinelOne integration as a connector task
A connection needs a schedule and a site. The schedule sets when the sync runs, and the site is where runZero creates any new SentinelOne-only assets.
- Activate a connection to SentinelOne. You can reach every available third-party connection from the integrations page, your inventory, or the tasks page.
- Choose the credentials you added earlier. If they are not listed, check that the credentials have access to the organization you are in.
- Enter a name for the task, like
SentinelOne sync. - Schedule the sync to run once or on a recurring schedule. The schedule starts on the date and time you set.
- Under Task configuration, choose the site to add your assets to.
- To skip importing software, switch the Import Software toggle to No.
- To skip importing vulnerabilities, switch the Import Vulnerabilities toggle to No.
- With the Import Vulnerabilities toggle set to Yes, use the Severities checkboxes to choose which vulnerability severities to import.
- To leave out assets that runZero has not scanned, switch the Exclude unknown assets toggle to Yes. By default, the integration includes them.
- Activate the connection when you are done. The sync runs on the defined schedule, and the Scheduled tasks page shows when the next sync will occur.
Step 4b: Configure the SentinelOne integration as a scan probe
- Create a new scan task or select a future or recurring scan task from your Tasks page.
- Add or update the scan parameters to match any additional requirements.
- On the Probes and SNMP tab, choose which additional probes to include, set the SentinelOne toggle to Yes, and change any default options as needed.
- On the Credentials tab, set the toggle to Yes for the SentinelOne credential you want to use.
- Click Initialize scan to save the scan task. It runs immediately or at the scheduled time.
Step 5: View SentinelOne assets and software
After a successful sync, go to your inventory to view your SentinelOne assets. They show a SentinelOne icon in the Source column.
The integration also gathers details about installed software. Go to Inventory > Software to view the software data from SentinelOne. To search and filter that software, use the software instance inventory keywords.
To filter to SentinelOne assets, run one of these queries:
- View all SentinelOne assets:
source:SentinelOne - Find assets that have a SentinelOne agent installed:
edr.name:SentinelOne - Find Windows assets, excluding servers, that are missing a SentinelOne agent:
os:windows and not type:server and not edr.name:SentinelOne
Click an asset to see its attributes. runZero shows the attributes returned by the SentinelOne API, except policies.
Troubleshooting
If you are having trouble with this integration, the questions and answers below may help.
Why is the SentinelOne integration unable to connect?
- Check whether the SentinelOne integration is returning any data.
- Query the inventory rather than the task details to review all the data available from this integration.
- In some cases, an integration’s configuration limits how much data reaches the runZero console.
- Some integrations require specific actions that are easy to overlook. If you miss a step during setup, the integration may not work correctly. Review this page and follow the steps exactly.
- If the SentinelOne integration can’t connect, check the task log for errors. Common errors include:
- 500: server error, unable to connect to the endpoint
- 404: hitting an unknown endpoint on the server
- 403: not authorized, likely a credential issue
- If SentinelOne is on-premises, verify that the integration task runs from an Explorer with access to the SentinelOne host.