Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[SentinelOne] add agent.id to all agent related data collected from SentinelOne #9879

Open
paul-tavares opened this issue May 15, 2024 · 1 comment
Labels
enhancement New feature or request Integration:SentinelOne Sentinel One Team:Security-Service Integrations Security Service Integrations Team

Comments

@paul-tavares
Copy link
Contributor

Description

Two requests with regards to the SentinelOne Integration:

  1. For every document streamed to ES by the integration, if the data is associated with a SentinelOne agent, include the agent's id in the ES document (sentinel_one.[source_type].agent.id)
  2. Change the default intervals for the data pulling to 30s for all data streams

Background

Opened as a result of discussion here: #9313 (comment)

Changes requested are in support of Security Solution's Bi-Directional Response Actions feature which enables our SIEM users to send actions to SentinelOne Agents directly from Kibana.

@paul-tavares paul-tavares added enhancement New feature or request Integration:SentinelOne Sentinel One Team:Security-Service Integrations Security Service Integrations Team labels May 15, 2024
@elasticmachine
Copy link

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request Integration:SentinelOne Sentinel One Team:Security-Service Integrations Security Service Integrations Team
Projects
None yet
Development

No branches or pull requests

2 participants