edr.sentinelone
Introduction
The tags beginning with edr.sentinelone
identify events generated by SentinelOne's platform.
Valid tags and data tables
The full tag must have at least 3 levels. The first two are fixed as edr.sentinelone
. The third level identifies the type of events sent, and the fourth level indicates the event subtype.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
SentinelOne agent events |
|
|
|
| |
SentinelOne Deep Visibility |
|
|
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
SentinelOne management events |
|
|
How is the data sent to Devo?
To send events to the edr.sentinelone.dv
tables, you must use the SentinelOne Deep Visibility with Cloud Funnel collector.
Table structure
These are the fields displayed in these tables: