Imports detected threats, agent inventory, alerts, activities, and IOCs from your SentinelOne console.
For the general flow of adding a source, see Connect Data Sources.
Before you start
SentinelOne account with Admin or Service User role
URL of your SentinelOne instance (e.g., https://yourcompany.sentinelone.net)
Step 1 — Generate an API token
Sign in to your SentinelOne console
Avatar top right → My User
API Token section → Generate
Copy the displayed token immediately
Step 2 — (Recommended) Create a dedicated Service User
Settings → Users → Service Users
Actions → Create New Service User
Name: HARVEN, role: Viewer
Copy the generated API token
What to enter in HARVEN
URL — Full URL of your instance (with https://) (Address bar of your SentinelOne console)
Token — API token generated from My User or Service Users (SentinelOne → My User → API Token)
What HARVEN reads
threats — Detected threats: identification (threat_name, classification, mitigation_status), context (agent_computer_name, file_sha256, in_quarantine)
agents — Protected agents: identification (computer_name, os_type, agent_version), status (is_active, is_infected, threat_count, scan_status), network (last_ip_to_mgmt, external_ip)
alerts — Security alerts: detection (rule_name, severity, source_process_name)
activities — Activity log: activity (activity_type, description, user_email)
iocs — Indicators of compromise: IOC (value, ioc_type, source, valid_until)
Official documentation
Need help? Contact [email protected].