Welcome › Forums › Integrations › SentinelOne – syslog forwarding
- This topic is empty.
Viewing 1 post (of 1 total)
- AuthorPosts
- May 23, 2022 at 3:32 pm #3290Mike RiforgiateKeymaster
Configure SentinelOne to send logs to Precinct
Open the SentinelOne Admin Console. Configure SentinelOne to send logs to your Syslog server.
- Select your site.
- In the left side menu, click the slider icon [⊶] to open the Settings menu.
- Open the INTEGRATIONS tab, and fill in the details:
- Under Types, select SYSLOG.
- Toggle the button to enable SYSLOG.
- Host – Enter your public SYSLOG server IP address and port.
- Formatting – Select CEF2.
- Save your changes.
Configure SentinelOne to send notifications
In the same screen, open the NOTIFICATIONS tab, and fill in the details:
Under Notification Types, check all options under Syslog notifications.
We recommend enabling all notification options to send Syslog logs for full Precinct incident enrichment.
- AuthorPosts
Viewing 1 post (of 1 total)
- You must be logged in to reply to this topic.