Document toolboxDocument toolbox

av.sentinelone

Introduction

The tags beginning with av.sentinelone identify events generated by antivirus products belonging to SentinelOne.

Valid tags and data tables 

The full tag must have 3 levels. The first two are fixed as av.sentinelone. The third level identifies the type of events sent.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

SentinelOne Endpoint Protection Platform (EPP)

av.sentinelone.events

av.sentinelone.events

av.sentinelone.rfc_5424

av.sentinelone.rfc_5424

For more information, read more About Devo tags.

Table structure

These are the fields displayed in this table: