FortiSIEM Discussions
adem_netsys
Contributor

SIEM: SentinelOne Parser

Hi guys,

 

Anyone has sentinelone parser? It hits NGParser in default and so I can't do any new development.

 

Thanks

4 REPLIES 4
FSM_FTNT
Staff
Staff

SentinelOne is supported https://docs.fortinet.com/document/fortisiem/7.1.3/external-systems-configuration-guide/780558/senti...

 

Can you provide a sample event so that I can check?

Change/obfuscate any sensitive values before posting.

adem_netsys

Hi @FSM_FTNT 

 

We get logs with the help of api, so it does not come in CEF format.

FSM_FTNT
Staff
Staff

How have you integrated with their API, through the generic HTTP API Poller?

 

https://docs.fortinet.com/document/fortisiem/7.1.3/external-systems-configuration-guide/412973/gener...

adem_netsys

Yes, i did this way.