HARVEN
HARVEN
Docs
  • Docs
  • Changelog
  • Support portal
    • Connect Microsoft Entra ID
    • Connect Microsoft Defender for Endpoint
    • Connect Microsoft Intune
    • Connect Microsoft Azure
    • Connect Amazon Web Services (AWS)
    • Connect Scaleway
    • CSV Import
    • Connect NinjaOne (NinjaRMM)
    • Connect SharePoint
    • Connect Workspace ONE Intelligence
    • Connect Sekoia.io
    • Connect Google BigQuery
    • Connect Google Workspace
    • Connect SentinelOne
    • Connect Opsgenie (Atlassian)

Connect SentinelOne

Imports detected threats, agent inventory, alerts, activities, and IOCs from your SentinelOne console.

For the general flow of adding a source, see Connect Data Sources.

Before you start

  • SentinelOne account with Admin or Service User role

  • URL of your SentinelOne instance (e.g., https://yourcompany.sentinelone.net)

Step 1 — Generate an API token

  1. Sign in to your SentinelOne console

  2. Avatar top right → My User

  3. API Token section → Generate

  4. Copy the displayed token immediately

Step 2 — (Recommended) Create a dedicated Service User

  1. Settings → Users → Service Users

  2. Actions → Create New Service User

  3. Name: HARVEN, role: Viewer

  4. Copy the generated API token

What to enter in HARVEN

  • URL — Full URL of your instance (with https://) (Address bar of your SentinelOne console)

  • Token — API token generated from My User or Service Users (SentinelOne → My User → API Token)

What HARVEN reads

  • threats — Detected threats: identification (threat_name, classification, mitigation_status), context (agent_computer_name, file_sha256, in_quarantine)

  • agents — Protected agents: identification (computer_name, os_type, agent_version), status (is_active, is_infected, threat_count, scan_status), network (last_ip_to_mgmt, external_ip)

  • alerts — Security alerts: detection (rule_name, severity, source_process_name)

  • activities — Activity log: activity (activity_type, description, user_email)

  • iocs — Indicators of compromise: IOC (value, ioc_type, source, valid_until)

Official documentation

  • SentinelOne API Documentation


Need help? Contact [email protected].

PrevConnect Google Workspace
NextConnect Opsgenie (Atlassian)
Was this helpful?